Security Advisory

CVE-2016-11020

9.8
CRITICAL

Vulnerability Description

Kunena before 5.0.4 does not restrict avatar file extensions to gif, jpeg, jpg, and png. This can lead to XSS and remote code execution.
Published Date February 25, 2020
Official Source NIST NVD Advisory