VYPR
High severity8.8NVD Advisory· Published Apr 22, 2019· Updated Jun 17, 2026

CVE-2019-11447

CVE-2019-11447

Description

An issue was discovered in CutePHP CuteNews 2.1.2. An attacker can infiltrate the server through the avatar upload process in the profile area via the avatar_file field to index.php?mod=main&opt=personal. There is no effective control of $imgsize in /core/modules/dashboard.php. The header content of a file can be changed and the control can be bypassed for code execution. (An attacker can use the GIF header for this.)

AI Insight

LLM-synthesized narrative grounded in this CVE's description and references.

Affected products

2
  • Cutephp/Cutenews2 versions
    cpe:2.3:a:cutephp:cutenews:2.1.2:*:*:*:*:*:*:*+ 1 more
    • cpe:2.3:a:cutephp:cutenews:2.1.2:*:*:*:*:*:*:*
    • (no CPE)range: = 2.1.2

Patches

Vulnerability mechanics

References

3

News mentions

0

No linked articles in our index yet.