Show filters
20 Total Results
Displaying 11-20 of 20
Sort by:
Attacker Value
Unknown

CVE-2023-47650

Disclosure Date: November 18, 2023 (last updated February 25, 2025)
Cross-Site Request Forgery (CSRF) vulnerability in Peter Sterling Add Local Avatar.This issue affects Add Local Avatar: from n/a through 12.1.
Attacker Value
Unknown

CVE-2023-46621

Disclosure Date: November 08, 2023 (last updated February 25, 2025)
Unauth. Reflected Cross-Site Scripting (XSS) vulnerability in Enej Bajgoric / Gagan Sandhu / CTLT DEV User Avatar plugin <= 1.4.11 versions.
Attacker Value
Unknown

CVE-2023-4798

Disclosure Date: October 16, 2023 (last updated October 24, 2023)
The User Avatar WordPress plugin before 1.2.2 does not properly sanitize and escape certain of its shortcodes attributes, which could allow relatively low-privileged users like contributors to conduct Stored XSS attacks.
Attacker Value
Unknown

CVE-2021-24672

Disclosure Date: October 18, 2021 (last updated February 23, 2025)
The One User Avatar WordPress plugin before 2.3.7 does not escape the link and target attributes of its shortcode, allowing users with a role as low as Contributor to perform Stored Cross-Site Scripting attacks
Attacker Value
Unknown

CVE-2021-24675

Disclosure Date: October 18, 2021 (last updated February 23, 2025)
The One User Avatar WordPress plugin before 2.3.7 does not check for CSRF when updating the Avatar in page where the [avatar_upload] shortcode is embed. As a result, attackers could make logged in user change their avatar via a CSRF attack
Attacker Value
Unknown

CVE-2019-10377

Disclosure Date: August 07, 2019 (last updated October 26, 2023)
A missing permission check in Jenkins Avatar Plugin 1.2 and earlier allows attackers with Overall/Read access to change the avatar of any user of Jenkins.
Attacker Value
Unknown

CVE-2018-9205

Disclosure Date: April 04, 2018 (last updated November 26, 2024)
Vulnerability in avatar_uploader v7.x-1.0-beta8 , The code in view.php doesn't verify users or sanitize the file path.
0
Attacker Value
Unknown

CVE-2015-2087

Disclosure Date: February 26, 2015 (last updated October 05, 2023)
Unrestricted file upload vulnerability in the Avatar Uploader module before 6.x-1.3 for Drupal allows remote authenticated users to execute arbitrary PHP code by uploading a file with a PHP extension, then accessing it via unspecified vectors.
0
Attacker Value
Unknown

CVE-2014-9155

Disclosure Date: December 01, 2014 (last updated October 05, 2023)
Directory traversal vulnerability in the Avatar Uploader module 6.x-1.x before 6.x-1.2 and 7.x-1.x before 7.x-1.0-beta6 for Drupal allows remote authenticated users to read arbitrary files via a .. (dot dot) in the path of a cropped picture in the uploader panel.
0
Attacker Value
Unknown

CVE-2006-2530

Disclosure Date: May 22, 2006 (last updated October 04, 2023)
avatar_upload.asp in Avatar MOD 1.3 for Snitz Forums 3.4, and possibly other versions, allows remote attackers to bypass file type checks and upload arbitrary files via a null byte in the file name, as discovered by the Codescan product.
0