- 
    Bug 
- 
    Resolution: Fixed
- 
    Major 
- 
    3.0.8
- 
    None
The code in download/file.php
| $filename = $_GET['avatar']; | 
should be adjusted to use function request_var() to get $filename value.
Direct use of $_GET is known as insecure option.

