CVE-2019-11447

HIGH EXPLOITED IN THE WILD

CutePHP CuteNews 2.1.2 - Code Injection

Title source: llm
STIX 2.1

Exploitation Summary

CVE-2019-11447 has been observed exploited in the wild (reported by VulnCheck KEV, InTheWild.io). EIP tracks 8 public exploits from researchers including Musyoka Ian, AkkuS, thewhiteh4t.

AI-analyzed exploit summary This exploit targets CVE-2019-11447 in CuteNews 2.1.2, achieving remote code execution by uploading a malicious PHP file disguised as an avatar. It includes credential extraction, user registration, and a reverse shell-like interactive command execution.

Description

An issue was discovered in CutePHP CuteNews 2.1.2. An attacker can infiltrate the server through the avatar upload process in the profile area via the avatar_file field to index.php?mod=main&opt=personal. There is no effective control of $imgsize in /core/modules/dashboard.php. The header content of a file can be changed and the control can be bypassed for code execution. (An attacker can use the GIF header for this.)

Exploits (8)

exploitdb WORKING POC VERIFIED
by Musyoka Ian · pythonwebappsphp
https://www.exploit-db.com/exploits/48800

This exploit targets CVE-2019-11447 in CuteNews 2.1.2, achieving remote code execution by uploading a malicious PHP file disguised as an avatar. It includes credential extraction, user registration, and a reverse shell-like interactive command execution.

Classification
Working Poc 95%
Attack Type
Rce
Complexity
Moderate
Reliability
Reliable
Target: CuteNews 2.1.2
Auth required
Prerequisites: Target URL with vulnerable CuteNews installation · Network access to the target
devstral-2 · analyzed Feb 16, 2026 Full analysis →
exploitdb WORKING POC VERIFIED
by AkkuS · rubyremotephp
https://www.exploit-db.com/exploits/46698

This Metasploit module exploits a remote code execution vulnerability in CuteNews prior to 2.1.2 by bypassing file upload restrictions via manipulated GIF headers. It authenticates as a user, uploads a malicious PHP file disguised as an avatar, and executes it.

Classification
Working Poc 100%
Attack Type
Rce
Complexity
Moderate
Reliability
Reliable
Target: CuteNews < 2.1.2
Auth required
Prerequisites: Valid user credentials · Access to the avatar upload functionality
devstral-2 · analyzed Feb 16, 2026 Full analysis →
nomisec WORKING POC 9 stars
by thewhiteh4t · remote
https://github.com/thewhiteh4t/cve-2019-11447

This repository contains a functional Python exploit for CVE-2019-11447, an arbitrary file upload vulnerability in CutePHP CuteNews 2.1.2. The script automates authentication, payload upload, and reverse shell execution.

Classification
Working Poc 100%
Attack Type
Rce
Complexity
Moderate
Reliability
Reliable
Target: CutePHP CuteNews 2.1.2
Auth required
Prerequisites: Valid credentials for the target CuteNews installation · Network access to the target · Listener setup for reverse shell
devstral-2 · analyzed Feb 18, 2026 Full analysis →
nomisec WORKING POC 1 stars
by CRFSlick · remote-auth
https://github.com/CRFSlick/CVE-2019-11447-POC

This repository contains a functional exploit for CVE-2019-11447, which allows remote code execution in CuteNews 2.1.2 via a malicious avatar upload. The exploit bypasses file type validation by embedding PHP code in a GIF file's metadata and leverages authenticated file upload to achieve RCE.

Classification
Working Poc 100%
Attack Type
Rce
Complexity
Moderate
Reliability
Reliable
Target: CuteNews 2.1.2
Auth required
Prerequisites: Valid credentials for CuteNews · Access to the avatar upload functionality
devstral-2 · analyzed Feb 18, 2026 Full analysis →
nomisec WORKING POC 1 stars
by khuntor · remote
https://github.com/khuntor/CVE-2019-11447-EXP

This repository contains a functional exploit for CVE-2019-11447, targeting CuteNews 2.1.2. The exploit leverages an avatar upload vulnerability to achieve remote code execution by uploading a malicious PHP shell.

Classification
Working Poc 95%
Attack Type
Rce
Complexity
Moderate
Reliability
Reliable
Target: CuteNews 2.1.2
Auth required
Prerequisites: Access to the CuteNews application · Valid user credentials or ability to register a new user
devstral-2 · analyzed Feb 18, 2026 Full analysis →
nomisec WORKING POC
by substing · remote-auth
https://github.com/substing/CVE-2019-11447_reverse_shell_upload

This repository contains a functional exploit for CVE-2019-11447, targeting CuteNews 2.1.2. The exploit leverages poor file upload checks to upload a PHP reverse shell, achieving remote code execution (RCE).

Classification
Working Poc 100%
Attack Type
Rce
Complexity
Moderate
Reliability
Reliable
Target: CuteNews 2.1.2
Auth required
Prerequisites: Valid credentials for a CuteNews account · Network access to the target application
devstral-2 · analyzed Feb 18, 2026 Full analysis →
nomisec WORKING POC
by ColdFusionX · remote-auth
https://github.com/ColdFusionX/CVE-2019-11447_CuteNews-AvatarUploadRCE

This repository contains a functional exploit for CVE-2019-11447, which targets an authenticated remote code execution vulnerability in CuteNews 2.1.2 via avatar upload. The exploit automates user registration/login, uploads a malicious PHP file disguised as a GIF, and triggers execution.

Classification
Working Poc 95%
Attack Type
Rce
Complexity
Moderate
Reliability
Reliable
Target: CuteNews 2.1.2
Auth required
Prerequisites: Valid credentials or ability to register a user · Network access to the target CuteNews instance
devstral-2 · analyzed Feb 18, 2026 Full analysis →
nomisec WORKING POC
by mt-code · remote-auth
https://github.com/mt-code/CVE-2019-11447

This repository contains a functional exploit for CVE-2019-11447, targeting CuteNews 2.1.2. The exploit leverages poor file upload checks during avatar uploads to achieve remote code execution (RCE) by uploading a malicious PHP shell.

Classification
Working Poc 95%
Attack Type
Rce
Complexity
Moderate
Reliability
Reliable
Target: CuteNews 2.1.2
Auth required
Prerequisites: Valid CuteNews user credentials · Access to the CuteNews login page
devstral-2 · analyzed Feb 18, 2026 Full analysis →

References (3)

Core 3
Core References
Exploit, Third Party Advisory, VDB Entry exploit x_refsource_exploit-db
https://www.exploit-db.com/exploits/46698/

Scores

CVSS v3 8.8
EPSS 0.7371
EPSS Percentile 98.8%
Attack Vector NETWORK
CVSS:3.0/AV:N/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H

Details

VulnCheck KEV 2020-12-14
InTheWild.io 2020-11-10
CWE
CWE-434
Status published
Products (1)
cutephp/cutenews 2.1.2
Published Apr 22, 2019
Tracked Since Feb 18, 2026