Description
An issue was discovered in CutePHP CuteNews 2.1.2. An attacker can infiltrate the server through the avatar upload process in the profile area via the avatar_file field to index.php?mod=main&opt=personal. There is no effective control of $imgsize in /core/modules/dashboard.php. The header content of a file can be changed and the control can be bypassed for code execution. (An attacker can use the GIF header for this.)
In plain language
AI Worth attentionCVE-2019-11447 is a serious security flaw in CutePHP CuteNews 2.1.2 that can let an attacker get code onto your server through avatar image uploads; small businesses should act urgently if you use this exact version.
In CutePHP CuteNews 2.1.2, the avatar upload path (avatar_file) can be abused to bypass upload validation due to missing effective size/type control, allowing crafted file headers (e.g., GIF headers) to reach index.php?mod=main&opt=personal and execute attacker code.
What to do now
- Check whether your website is running CutePHP CuteNews 2.1.2.
- If it is, confirm whether you allow avatar/profile image uploads (or any “avatar upload” feature) for normal users.
- Apply the vendor’s available update/patch for this issue; if no fix is available for your version, plan an upgrade to a newer CuteNews release where a fix is included.
- Temporarily restrict avatar/profile uploads or disable the avatar upload feature until you can upgrade.
- Review web server and application logs for suspicious upload attempts and follow-up behavior after uploads (e.g., unexpected file changes or new server processes).
CVSS Vector Breakdown
AV:NAttack VectorAC:LAttack ComplexityPR:LPrivileges RequiredUI:NUser InteractionS:UScopeC:HConfidentialityI:HIntegrityA:HAvailabilityWeaknesses
Affected Products
Exploitability
Exploit details including PoC links, Metasploit modules, and scanner templates are available after registration.
View exploit detailsAttack Graph
Click technique nodes for MITRE ATT&CK details · drag to pan · Ctrl/⌘ + scroll to zoom, or go fullscreen.
MITRE ATT&CK
3 techniquesReferences
Unlock Complete Vulnerability Intelligence
Get the full picture for CVE-2019-11447 and every CVE in our database. Create a free account — no credit card required.
Create Free Account