Analysis and contextual insights are available on OpenCVE Cloud.
No vendor fix or workaround currently provided.
Additional remediation guidance may be available on OpenCVE Cloud.
Tracking
Sign in to view the affected projects.
No advisories yet.
Thu, 04 Jun 2026 14:30:00 +0000
| Type | Values Removed | Values Added |
|---|---|---|
| Metrics |
ssvc
|
Thu, 04 Jun 2026 13:30:00 +0000
| Type | Values Removed | Values Added |
|---|---|---|
| Description | A vulnerability was determined in mjperpinosa stumasy. The impacted element is an unknown function of the file application/PHP/objects/profiles/change_profile_image.php. Executing a manipulation of the argument pr_profile_image can lead to unrestricted upload. The attack may be launched remotely. The exploit has been publicly disclosed and may be utilized. This product operates on a rolling release basis, ensuring continuous delivery. Consequently, there are no version details for either affected or updated releases. The project was informed of the problem early through an issue report but has not responded yet. | |
| Title | mjperpinosa stumasy change_profile_image.php unrestricted upload | |
| First Time appeared |
Mjperpinosa
Mjperpinosa stumasy |
|
| Weaknesses | CWE-284 CWE-434 |
|
| CPEs | cpe:2.3:a:mjperpinosa:stumasy:*:*:*:*:*:*:*:* | |
| Vendors & Products |
Mjperpinosa
Mjperpinosa stumasy |
|
| References |
| |
| Metrics |
cvssV2_0
|
Status: PUBLISHED
Assigner: VulDB
Published:
Updated: 2026-06-04T13:48:22.393Z
Reserved: 2026-06-04T05:14:46.616Z
Link: CVE-2026-10807
Updated: 2026-06-04T13:48:18.940Z
Status : Deferred
Published: 2026-06-04T14:16:36.790
Modified: 2026-06-04T14:41:25.017
Link: CVE-2026-10807
No data.
OpenCVE Enrichment
Updated: 2026-06-05T10:08:04Z