Leaf · Leaf Admin · CVE-2019-14755
**Name of the Vulnerable Software and Affected Versions**
Leaf Admin version 61.9.0212.10
**Description**
The issue concerns the profile photo upload feature, which allows the unrestricted upload of files with dangerous types.
**Recommendations**
For Leaf Admin version 61.9.0212.10, consider restricting the types of files that can be uploaded through the profile photo upload feature to prevent potential exploitation. As a temporary workaround, consider disabling the profile photo upload feature until a more robust fix is available.