CVE-2016-11020
EUVD-2016-201125.02.2020, 19:15
Kunena before 5.0.4 does not restrict avatar file extensions to gif, jpeg, jpg, and png. This can lead to XSS and remote code execution.Enginsight
Affected Products (NVD)
| Vendor | Product | Version |
|---|---|---|
| kunena | kunena | 𝑥 < 5.0.4 |
𝑥
= Vulnerable software versions
Common Weakness Enumeration