CVE-2026-1107 | EyouCMS up to 1.7.1/5.0 Member Avatar Diyajax.php check_userinfo viewfile unrestricted upload (EUVD-2026-3190)
A vulnerability classified as critical was found in EyouCMS up to 1.7.1/5.0. Impacted is the function check_userinfo of the file Diyajax.php of the component Member Avatar Handler. Executing a manipulation of the argument viewfile can lead to unrestricted upload.
This vulnerability appears as CVE-2026-1107. The attack may be performed from remote. In addition, an exploit is available.
The vendor was contacted early about this disclosure but did not respond in any way.