- 
    
Bug
 - 
    Resolution: Fixed
 - 
    
Major
 - 
    3.0.8
 - 
    None
 
The code in download/file.php
					$filename = $_GET['avatar'];
			 | 
		
should be adjusted to use function request_var() to get $filename value.
Direct use of $_GET is known as insecure option.

