Security Advisory
CVE-2016-11020
9.8
CRITICAL
Vulnerability Description
Kunena before 5.0.4 does not restrict avatar file extensions to gif, jpeg, jpg, and png. This can lead to XSS and remote code execution.
Published Date
February 25, 2020
Official Source
NIST NVD Advisory