CVE-2019-9662: Jtbc PHP

High severity, CVSS 7.5. EPSS: 1.7% chance of exploitation in the next 30 days.

An issue was discovered in JTBC(PHP) 3.0.1.8. Its cache management module is flawed. An arbitrary file ending in "inc.php" can be deleted via a console/cache/manage.php?type=action&action=batch&batch=delete&ids=../ substring.

Affected products

  • Jtbc Jtbc PHP: version 3.0.1.8 only

Published 2019-03-11. Last modified 2026-06-17.