An issue was discovered in CutePHP CuteNews 2.1.2. An attacker can infiltrate the server through the avatar upload process in the profile area via the avatar_file field to index.php?mod=main&opt=personal. There is no effective control of $imgsize in /core/modules/dashboard.php. The header content of a file can be changed and the control can be bypassed for code execution. (An attacker can use the GIF header for this.)
Metrics
Affected Vendors & Products
Advisories
No advisories yet.
Fixes
Solution
No solution given by the vendor.
Workaround
No workaround given by the vendor.
References
History
No history.
Projects
Sign in to view the affected projects.
Status: PUBLISHED
Assigner: mitre
Published:
Updated: 2024-08-04T22:55:39.696Z
Reserved: 2019-04-21T00:00:00
Link: CVE-2019-11447
No data.
Status : Modified
Published: 2019-04-22T11:29:06.110
Modified: 2024-11-21T04:21:05.840
Link: CVE-2019-11447
No data.
OpenCVE Enrichment
No data.
Weaknesses