High severity7.8NVD Advisory· Published May 19, 2020· Updated Jun 17, 2026
CVE-2020-11807
CVE-2020-11807
Description
Because of Unrestricted Upload of a File with a Dangerous Type, Sourcefabric Newscoop 4.4.7 allows an authenticated user to execute arbitrary PHP code (and sometimes terminal commands) on a server by making an avatar update and then visiting the avatar file under the /images/ path.
AI Insight
LLM-synthesized narrative grounded in this CVE's description and references.
Affected products
2- Sourcefabric/Newscoopdescription
- Range: =4.4.7
Patches
Vulnerability mechanics
References
2- github.com/sourcefabric/Newscoop/blob/3df835637609a5a42530b2a4611177c634ad6274/newscoop/library/Newscoop/Image/ImageService.phpnvdPatchThird Party Advisory
- gist.github.com/V-Rico/82e9e52ac451dc20eef87b0999b3b1eenvdExploitThird Party Advisory
News mentions
0No linked articles in our index yet.