Kunena before 5.0.4 does not restrict avatar file extensions to gif, jpeg, jpg, and png. This can lead to XSS and remote code execution.
References
Link | Resource |
---|---|
https://github.com/Kunena/Kunena-Forum/pull/5028 | Patch Third Party Advisory |
https://www.kunena.org/blog/179-kunena-5-0-4-released | Release Notes Vendor Advisory |
https://www.kunena.org/bugs/changelog | Release Notes Vendor Advisory |
History
No history.
MITRE Information
Status: PUBLISHED
Assigner: mitre
Published: 2020-02-24T17:04:35
Updated: 2020-02-28T22:05:40
Reserved: 2020-02-24T00:00:00
Link: CVE-2016-11020
JSON object: View
NVD Information
Status : Analyzed
Published: 2020-02-25T19:15:10.817
Modified: 2020-03-03T13:40:31.113
Link: CVE-2016-11020
JSON object: View
Redhat Information
No data.
CWE