CVE-2019-12099
14.05.2019, 21:29
In PHP-Fusion 9.03.00, edit_profile.php allows remote authenticated users to execute arbitrary code because includes/dynamics/includes/form_fileinput.php and includes/classes/PHPFusion/Installer/Lib/Core.settings.inc mishandle executable files during avatar upload.Enginsight
Vendor | Product | Version |
---|---|---|
php-fusion | php-fusion | 𝑥 < 9.03.00 |
𝑥
= Vulnerable software versions
Common Weakness Enumeration
References