← Back to CVE List

CVE-2020-11807

Published: 2020-05-19T16:15Z
Last Modified: 2024-11-21T04:58Z
Source: MITRE CVE List
License: MITRE-CVE-TOS
Because of Unrestricted Upload of a File with a Dangerous Type, Sourcefabric Newscoop 4.4.7 allows an authenticated user to execute arbitrary PHP code (and sometimes terminal commands) on a server by making an avatar update and then visiting the avatar file under the /images/ path. > MITRE Terms of Use apply – see LICENSE‑MITRE.txt