Stumasy · Stumasy · CVE-2026-10807
**Name of the Vulnerable Software and Affected Versions**
mjperpinosa stumasy (affected versions not specified)
**Description**
An unrestricted file upload issue exists in the file 'application/PHP/objects/profiles/change profile image.php'. A remote attacker can exploit this by manipulating the `pr profile image` argument, allowing the upload of unauthorized files.
**Recommendations**
At the moment, there is no information about a newer version that contains a fix for this vulnerability.
As a temporary workaround, restrict access to the file 'application/PHP/objects/profiles/change profile image.php' or avoid using the `pr profile image` argument until a fix is provided.