HIGH

CVE-2019-11447

CVSS v3

8.8

HIGH

EPSS Score

73.7%

exploit probability

CISA KEV

No

known exploited

Exploitation

SSVC status

Description

An issue was discovered in CutePHP CuteNews 2.1.2. An attacker can infiltrate the server through the avatar upload process in the profile area via the avatar_file field to index.php?mod=main&opt=personal. There is no effective control of $imgsize in /core/modules/dashboard.php. The header content of a file can be changed and the control can be bypassed for code execution. (An attacker can use the GIF header for this.)

Technical details

Published
4/22/2019

Frequently asked questions

What is CVE-2019-11447?

An issue was discovered in CutePHP CuteNews 2.1.2. An attacker can infiltrate the server through the avatar upload process in the profile area via the avatar_file field to index.php?mod=main&opt=personal. There is no effective control of $imgsize in /core/modules/dashboard.php. The header content of a file can be changed and the control can be bypassed for code execution. (An attacker can use the GIF header for this.)

Is CVE-2019-11447 actively exploited?

Active exploitation of CVE-2019-11447 has not been confirmed. The EPSS score is 73.7%, indicating the estimated probability of exploitation in the next 30 days.

What is the CVSS score for CVE-2019-11447?

CVE-2019-11447 has a CVSS v3 base score of 8.8 (HIGH severity).

Is CVE-2019-11447 affecting your environment?

Use isMalicious to check if any of your IPs or domains are associated with this vulnerability's IOCs.