VYPR
High severity7.8NVD Advisory· Published May 19, 2020· Updated Jun 17, 2026

CVE-2020-11807

CVE-2020-11807

Description

Because of Unrestricted Upload of a File with a Dangerous Type, Sourcefabric Newscoop 4.4.7 allows an authenticated user to execute arbitrary PHP code (and sometimes terminal commands) on a server by making an avatar update and then visiting the avatar file under the /images/ path.

AI Insight

LLM-synthesized narrative grounded in this CVE's description and references.

Affected products

3
  • cpe:2.3:a:sourcefabric:newscoop:4.4.7:*:*:*:*:*:*:*+ 1 more
    • cpe:2.3:a:sourcefabric:newscoop:4.4.7:*:*:*:*:*:*:*
    • (no CPE)range: = 4.4.7
  • Sourcefabric/Newscoopdescription

Patches

Vulnerability mechanics

References

2

News mentions

0

No linked articles in our index yet.