CVE-2018-9205 is a vulnerability in Drupal Avatar Uploader
Published on April 4, 2018
Vulnerability in avatar_uploader v7.x-1.0-beta8 , The code in view.php doesn't verify users or sanitize the file path.
Products Associated with CVE-2018-9205
Want to know whenever a new CVE is published for Drupal Avatar Uploader? stack.watch will email you.
Affected Versions
Robbin Zhao avatar_uploader:- Version unspecified and below 7.x-1.0-beta8 is affected.
Exploit Probability
EPSS
81.45%
Percentile
99.16%
EPSS (Exploit Prediction Scoring System) scores estimate the probability that a vulnerability will be exploited in the wild within the next 30 days. The percentile shows you how this score compares to all other vulnerabilities.