CVE-2017-14839

HIGH

TeamWork Photo Fusion - Arbitrary File Upload

Title source: llm
STIX 2.1

Exploitation Summary

EIP tracks 1 public exploit for CVE-2017-14839. PoCs published by Ihsan Sencan.

AI-analyzed exploit summary The exploit describes an arbitrary file upload vulnerability in Photo Fusion - Free Stock Photos Script. The vulnerable code allows authenticated users to upload files with arbitrary extensions, potentially leading to remote code execution if malicious files are uploaded.

Description

TeamWork Photo Fusion allows Arbitrary File Upload in changeAvatar and changeCover.

Exploits (1)

exploitdb WRITEUP
by Ihsan Sencan · textwebappsphp
https://www.exploit-db.com/exploits/42797

The exploit describes an arbitrary file upload vulnerability in Photo Fusion - Free Stock Photos Script. The vulnerable code allows authenticated users to upload files with arbitrary extensions, potentially leading to remote code execution if malicious files are uploaded.

Classification
Writeup 90%
Attack Type
Rce
Complexity
Trivial
Reliability
Reliable
Target: Photo Fusion - Free Stock Photos Script
Auth required
Prerequisites: Authenticated user access · Upload functionality enabled
devstral-2 · analyzed Feb 16, 2026 Full analysis →

References (1)

Core 1
Core References
Exploit, Third Party Advisory, VDB Entry exploit x_refsource_exploit-db
https://www.exploit-db.com/exploits/42797/

Scores

CVSS v3 8.8
EPSS 0.0352
EPSS Percentile 87.7%
Attack Vector NETWORK
CVSS:3.0/AV:N/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H

Details

CWE
CWE-434
Status published
Products (1)
teamworktec/photo_fusion
Published Sep 28, 2017
Tracked Since Feb 18, 2026