CVE-2019-11447

HIGH EXPLOITED IN THE WILD

CutePHP CuteNews 2.1.2 - Code Injection

Title source: llm

Description

An issue was discovered in CutePHP CuteNews 2.1.2. An attacker can infiltrate the server through the avatar upload process in the profile area via the avatar_file field to index.php?mod=main&opt=personal. There is no effective control of $imgsize in /core/modules/dashboard.php. The header content of a file can be changed and the control can be bypassed for code execution. (An attacker can use the GIF header for this.)

Exploits (10)

exploitdb WORKING POC VERIFIED
by Musyoka Ian · pythonwebappsphp
https://www.exploit-db.com/exploits/48800
exploitdb WORKING POC VERIFIED
by AkkuS · rubyremotephp
https://www.exploit-db.com/exploits/46698
nomisec WORKING POC 9 stars
by thewhiteh4t · remote
https://github.com/thewhiteh4t/cve-2019-11447
nomisec WORKING POC 1 stars
by CRFSlick · remote-auth
https://github.com/CRFSlick/CVE-2019-11447-POC
nomisec WORKING POC 1 stars
by khuntor · remote
https://github.com/khuntor/CVE-2019-11447-EXP
nomisec WORKING POC
by substing · remote-auth
https://github.com/substing/CVE-2019-11447_reverse_shell_upload
nomisec WORKING POC
by ColdFusionX · remote-auth
https://github.com/ColdFusionX/CVE-2019-11447_CuteNews-AvatarUploadRCE
nomisec WORKING POC
by mt-code · remote-auth
https://github.com/mt-code/CVE-2019-11447

Scores

CVSS v3 8.8
EPSS 0.7371
EPSS Percentile 98.8%
Attack Vector NETWORK
CVSS:3.0/AV:N/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H

Details

VulnCheck KEV 2020-12-14
InTheWild.io 2020-11-10
CWE
CWE-434
Status published
Products (1)
cutephp/cutenews 2.1.2
Published Apr 22, 2019
Tracked Since Feb 18, 2026