CVE-2024-48514

php-heic-to-jpg <= 1.0.5 is vulnerable to code injection (fixed in 1.0.6). An attacker who can upload heic images is able to execute code on the remote server via the file name. As a result, the CIA is no longer guaranteed. This affects php-heic-to-jpg 1.0.5 and below.
Configurations

No configuration.

History

No history.

Information

Published : 2024-10-24 18:15

Updated : 2024-12-19 16:15


NVD link : CVE-2024-48514

Mitre link : CVE-2024-48514

CVE.ORG link : CVE-2024-48514


JSON object : View

Products Affected

No product.

CWE
CWE-94

Improper Control of Generation of Code ('Code Injection')