CVE-2026-91849: WuzhiCMS Avatar Upload index.php setAvatar unrestricted upload
A security flaw has been discovered in WuzhiCMS up to 4.1.0. This affects the function member::setAvatar of the file /index.php?m=member&f=user&v=setAvatar of the component Avatar Upload. The manipulation of the argument File results in unrestricted upload. The attack can be executed remotely. The exploit has been released to the public and may be used for attacks. The project was informed of the problem early through an issue report but has not responded yet.
Affected Software
Event History
Frequently Asked Questions
What access does an attacker need to exploit this issue?
The attack is remote and requires low privileges. No user interaction is required.
Which deployments are known to be affected?
WuzhiCMS versions up to and including 4.1.0 are identified as affected. The issue is in the Avatar Upload functionality exposed through the member user setAvatar endpoint.
Is public exploit information available?
Yes. An exploit has been publicly released, which increases the likelihood of attempted exploitation.
Is a vendor fix available?
The available information does not identify a fix. The project was notified through an issue report but had not responded at the time of publication.