← Vulnerability feed

Vulnerability record · CVE-2019-11447 · published 22 April 2019

CVE-2019-11447: CuteNews avatar upload allows remote code execution

CCutephp · Cutenews

CuteNews 2.1.2 fails to properly validate uploaded avatar files in the profile area; the $imgsize check in /core/modules/dashboard.php can be bypassed by manipulating file headers, such as prepending a GIF header. An authenticated attacker can upload a file containing executable code and run it on the server.

8.8 CVSS 3.0 High EPSS 52% · top 1.1% CWE-434 · Unrestricted file upload
8.8CVSS 3.0 base score, v2 6.5
52%EPSS exploitation probability, 30 days
NoNot in CISA KEV
1Affected product versions listed by NVD
6References, 4 tagged exploit
17 Jun 2026Last modified by NVD

Description

An issue was discovered in CutePHP CuteNews 2.1.2. An attacker can infiltrate the server through the avatar upload process in the profile area via the avatar_file field to index.php?mod=main&opt=personal. There is no effective control of $imgsize in /core/modules/dashboard.php. The header content of a file can be changed and the control can be bypassed for code execution. (An attacker can use the GIF header for this.)

CVSS:3.0/AV:N/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H

Automated analysis

Generated by VULONE's analysis model from the NVD record, CISA KEV and EPSS data on 20 September 2026. Confidence: high.

high priorityCVSS 8.8 with public exploit code and very high EPSS, but exploitation requires an authenticated account and the product is not in KEV.

What it is

CuteNews 2.1.2 fails to properly validate uploaded avatar files in the profile area; the $imgsize check in /core/modules/dashboard.php can be bypassed by manipulating file headers, such as prepending a GIF header. An authenticated attacker can upload a file containing executable code and run it on the server.

Impact

Successful exploitation gives the attacker arbitrary code execution in the context of the web server, leading to full compromise of the application and potentially the host.

Attack surface

Reached over the network through the avatar upload field (avatar_file) at index.php?mod=main&opt=personal. The CVSS vector indicates low privileges are required (PR:L) and no user interaction (UI:N).

Exploitation

Public exploit code exists, including a Metasploit module and Exploit-DB entry, and EPSS is high (0.52272, 98.9th percentile), though the CVE is not listed in CISA KEV.

What to do

  • Upgrade CuteNews to a version later than 2.1.2 if available, or apply the vendor's fix for the avatar upload validation.
  • Restrict or disable avatar uploads until patched.
  • Validate uploaded files by content and extension, and store uploads outside the web root with execution disabled.
  • Enforce least privilege on the web server account to limit post-exploitation impact.

Detection

  • Monitor web server logs for POST requests to index.php?mod=main&opt=personal with avatar_file uploads.
  • Alert on files written to upload directories that contain executable content or GIF headers followed by PHP code.
  • Detect unexpected child processes spawned by the web server (e.g., shell, wget, curl).

This assessment is produced automatically and is not human-reviewed. Verify against the vendor advisory before acting on it.

Affected products

1 vulnerable configurations from NVD's CPE data, grouped by vendor and product.

References

Track CVE-2019-11447 inside VULONE

Watch it alongside the ransomware crews, C2 infrastructure and forum chatter that reference it, query it through the API and pull it into your SIEM over TAXII.

Start free Open in platform

Related vulnerabilities

Same products first, then exploited flaws of the same weakness class.

10.0CVE-2008-4557CuteNews Strawberry html.php code injection via text parameterThe html.php file in the wacko/highlight plugin of CuteNews.ru 1.1.1 (Strawberry) inserts the user-supplied text parameter into an executable regular…EPSS 45%analysed8.8CVE-2020-5558Cutephp cutenews code injection vulnerabilityCuteNews 2.0.1 allows remote authenticated attackers to execute arbitrary PHP code via unspecified vectors.EPSS 2.1%7.5CVE-2007-1153Cutephp cutenews code injection vulnerabilityMultiple PHP remote file inclusion vulnerabilities in CutePHP CuteNews 1.3.6 allow remote attackers to execute arbitrary PHP code via unspecified vec…EPSS 1.2%7.5CVE-2006-4445Cutephp cutenews vulnerabilityMultiple PHP remote file inclusion vulnerabilities in CuteNews 1.3.x allow remote attackers to execute arbitrary PHP code via a URL in the cutepath p…EPSS 1.8%7.5CVE-2005-3010Cutephp cutenews vulnerabilityDirect static code injection vulnerability in the flood protection feature in inc/shows.inc.php in CuteNews 1.4.0 and earlier allows remote attackers…EPSS 6.3%7.5CVE-2004-1660Cutephp cutenews vulnerabilityPHP remote file inclusion vulnerability in CuteNews 1.3.6 and earlier allows remote attackers to execute arbitrary PHP code via the cutepath paramete…EPSS 1.7%7.5CVE-2003-1240Cutephp cutenews code injection vulnerabilityPHP remote file inclusion vulnerability in CuteNews 0.88 allows remote attackers to execute arbitrary PHP code via a URL in the cutepath parameter in…EPSS 6.9%7.2CVE-2004-1573Aj-fork vulnerabilityThe documentation for AJ-Fork 167 implies that users should set permissions for users.db.php to 777, which allows local users to execute arbitrary PH…EPSS 0.46%

Source: NIST National Vulnerability Database (record CVE-2019-11447), CISA KEV, FIRST EPSS (scores of 2026-09-26). This page is refreshed as NVD updates the record.