VYPR
Critical severity9.8NVD Advisory· Published Dec 3, 2019· Updated Jun 17, 2026

CVE-2019-16885

CVE-2019-16885

Description

In OkayCMS through 2.3.4, an unauthenticated attacker can achieve remote code execution by injecting a malicious PHP object via a crafted cookie. This could happen at two places: first in view/ProductsView.php using the cookie price_filter, and second in api/Comparison.php via the cookie comparison.

AI Insight

LLM-synthesized narrative grounded in this CVE's description and references.

Affected products

3
  • OkayCMS/OkayCMSllm-fuzzy2 versions
    <=2.3.4+ 1 more
    • (no CPE)range: <=2.3.4
    • cpe:2.3:a:okay-cms:okaycms:*:*:*:*:*:*:*:*range: <=2.3.4
  • OkayCMS/OkayCMSdescription

Patches

Vulnerability mechanics

References

3

News mentions

0

No linked articles in our index yet.