CVE-2019-9002: Pixeline Bugs
Critical severity, CVSS 9.8. EPSS: 2.4% chance of exploitation in the next 30 days.
An issue was discovered in Tiny Issue 1.3.1 and pixeline Bugs through 1.3.2c. install/config-setup.php allows remote attackers to execute arbitrary PHP code via the database_host parameter if the installer remains present in its original directory after installation is completed.
Affected products
- Pixeline Bugs: up to and including 1.3.2c
- Tiny Issue Project Tiny Issue: version 1.3.1 only
Published 2019-02-22. Last modified 2026-06-17.