Description
An issue was discovered in CutePHP CuteNews 2.1.2. An attacker can infiltrate the server through the avatar upload process in the profile area via the avatar_file field to index.php?mod=main&opt=personal. There is no effective control of $imgsize in /core/modules/dashboard.php. The header content of a file can be changed and the control can be bypassed for code execution. (An attacker can use the GIF header for this.)
Analysis and contextual insights are available on OpenCVE Cloud.
Remediation
No vendor fix or workaround currently provided.
Additional remediation guidance may be available on OpenCVE Cloud.
Tracking
Sign in to view the affected projects.
Advisories
No advisories yet.
References
History
No history.
Status: PUBLISHED
Assigner: mitre
Published:
Updated: 2024-08-04T22:55:39.696Z
Reserved: 2019-04-21T00:00:00.000Z
Link: CVE-2019-11447
No data.
Status : Modified
Published: 2019-04-22T11:29:06.110
Modified: 2024-11-21T04:21:05.840
Link: CVE-2019-11447
No data.
OpenCVE Enrichment
No data.
Weaknesses