drupal avatar-uploader CVE-2018-9205 is a vulnerability in Drupal Avatar Uploader
Published on April 4, 2018

Vulnerability in avatar_uploader v7.x-1.0-beta8 , The code in view.php doesn't verify users or sanitize the file path.

NVD


Products Associated with CVE-2018-9205

Want to know whenever a new CVE is published for Drupal Avatar Uploader? stack.watch will email you.

 

Affected Versions

Robbin Zhao avatar_uploader:

Exploit Probability

EPSS
81.45%
Percentile
99.16%

EPSS (Exploit Prediction Scoring System) scores estimate the probability that a vulnerability will be exploited in the wild within the next 30 days. The percentile shows you how this score compares to all other vulnerabilities.