VYPR

Avatar Upload

by WuzhiCMS

CVEs (1)

  • CVE-2026-91849MedSep 15, 2026
    risk 0.41cvss 6.3epss

    A security flaw has been discovered in WuzhiCMS up to 4.1.0. This affects the function member::setAvatar of the file /index.php?m=member&f=user&v=setAvatar of the component Avatar Upload. The manipulation of the argument File results in unrestricted upload. The attack can be…