Vulnerability record · CVE-2019-11447 · published 22 April 2019
CVE-2019-11447: CuteNews avatar upload allows remote code execution
CCutephp · Cutenews
CuteNews 2.1.2 fails to properly validate uploaded avatar files in the profile area; the $imgsize check in /core/modules/dashboard.php can be bypassed by manipulating file headers, such as prepending a GIF header. An authenticated attacker can upload a file containing executable code and run it on the server.
Description
An issue was discovered in CutePHP CuteNews 2.1.2. An attacker can infiltrate the server through the avatar upload process in the profile area via the avatar_file field to index.php?mod=main&opt=personal. There is no effective control of $imgsize in /core/modules/dashboard.php. The header content of a file can be changed and the control can be bypassed for code execution. (An attacker can use the GIF header for this.)
CVSS:3.0/AV:N/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H
Automated analysis
high priorityCVSS 8.8 with public exploit code and very high EPSS, but exploitation requires an authenticated account and the product is not in KEV.
What it is
CuteNews 2.1.2 fails to properly validate uploaded avatar files in the profile area; the $imgsize check in /core/modules/dashboard.php can be bypassed by manipulating file headers, such as prepending a GIF header. An authenticated attacker can upload a file containing executable code and run it on the server.
Impact
Successful exploitation gives the attacker arbitrary code execution in the context of the web server, leading to full compromise of the application and potentially the host.
Attack surface
Reached over the network through the avatar upload field (avatar_file) at index.php?mod=main&opt=personal. The CVSS vector indicates low privileges are required (PR:L) and no user interaction (UI:N).
Exploitation
Public exploit code exists, including a Metasploit module and Exploit-DB entry, and EPSS is high (0.52272, 98.9th percentile), though the CVE is not listed in CISA KEV.
What to do
- Upgrade CuteNews to a version later than 2.1.2 if available, or apply the vendor's fix for the avatar upload validation.
- Restrict or disable avatar uploads until patched.
- Validate uploaded files by content and extension, and store uploads outside the web root with execution disabled.
- Enforce least privilege on the web server account to limit post-exploitation impact.
Detection
- Monitor web server logs for POST requests to index.php?mod=main&opt=personal with avatar_file uploads.
- Alert on files written to upload directories that contain executable content or GIF headers followed by PHP code.
- Detect unexpected child processes spawned by the web server (e.g., shell, wget, curl).
This assessment is produced automatically and is not human-reviewed. Verify against the vendor advisory before acting on it.
Affected products
1 vulnerable configurations from NVD's CPE data, grouped by vendor and product.
References
| Link | Tags |
|---|---|
| http://packetstormsecurity.com/files/159134/CuteNews-2.1.2-Remote-Code-Execution.html | |
| http://pentest.com.tr/exploits/CuteNews-2-1-2-Remote-Code-Execution-Metasploit.html | ExploitThird Party Advisory |
| https://www.exploit-db.com/exploits/46698/ | ExploitThird Party AdvisoryVDB Entry |
| http://packetstormsecurity.com/files/159134/CuteNews-2.1.2-Remote-Code-Execution.html | |
| http://pentest.com.tr/exploits/CuteNews-2-1-2-Remote-Code-Execution-Metasploit.html | ExploitThird Party Advisory |
| https://www.exploit-db.com/exploits/46698/ | ExploitThird Party AdvisoryVDB Entry |
Track CVE-2019-11447 inside VULONE
Watch it alongside the ransomware crews, C2 infrastructure and forum chatter that reference it, query it through the API and pull it into your SIEM over TAXII.
Related vulnerabilities
Same products first, then exploited flaws of the same weakness class.
Source: NIST National Vulnerability Database (record CVE-2019-11447), CISA KEV, FIRST EPSS (scores of 2026-09-26). This page is refreshed as NVD updates the record.