Exploitation Summary
EIP tracks 1 public exploit for CVE-2017-14839. PoCs published by Ihsan Sencan.
AI-analyzed exploit summary The exploit describes an arbitrary file upload vulnerability in Photo Fusion - Free Stock Photos Script. The vulnerable code allows authenticated users to upload files with arbitrary extensions, potentially leading to remote code execution if malicious files are uploaded.
Description
TeamWork Photo Fusion allows Arbitrary File Upload in changeAvatar and changeCover.
Exploits (1)
The exploit describes an arbitrary file upload vulnerability in Photo Fusion - Free Stock Photos Script. The vulnerable code allows authenticated users to upload files with arbitrary extensions, potentially leading to remote code execution if malicious files are uploaded.
References (1)
Scores
CVSS:3.0/AV:N/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H