ZeroHour

CVE-2016-11020

CVSS 3.1
9.8 critical
EPSS
3%p86
Published
()
Modified
Description

Kunena before 5.0.4 does not restrict avatar file extensions to gif, jpeg, jpg, and png. This can lead to XSS and remote code execution.

Vendors
kunena
Products
kunena
Weakness
CWE-434
Vector
CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H

In the news

No ingested article mentions this CVE yet.