Lucene search

K
prionPRIOn knowledge basePRION:CVE-2020-11807
HistoryMay 19, 2020 - 4:15 p.m.

Unrestricted file upload

2020-05-1916:15:00
PRIOn knowledge base
www.prio-n.com
2

7.8 High

AI Score

Confidence

High

0.0005 Low

EPSS

Percentile

18.0%

Because of Unrestricted Upload of a File with a Dangerous Type, Sourcefabric Newscoop 4.4.7 allows an authenticated user to execute arbitrary PHP code (and sometimes terminal commands) on a server by making an avatar update and then visiting the avatar file under the /images/ path.

CPENameOperatorVersion
newscoopeq4.4.7

7.8 High

AI Score

Confidence

High

0.0005 Low

EPSS

Percentile

18.0%

Related for PRION:CVE-2020-11807