Kunena before 5.0.4 does not restrict avatar file extensions to gif, jpeg, jpg, and png. This can lead to XSS and remote code execution.
History

No history.

cve-icon MITRE

Status: PUBLISHED

Assigner: mitre

Published: 2020-02-24T17:04:35

Updated: 2024-08-06T03:47:33.913Z

Reserved: 2020-02-24T00:00:00

Link: CVE-2016-11020

cve-icon Vulnrichment

No data.

cve-icon NVD

Status : Analyzed

Published: 2020-02-25T19:15:10.817

Modified: 2020-03-03T13:40:31.113

Link: CVE-2016-11020

cve-icon Redhat

No data.