PT-2025-3026 · Unknown · Image Picker+1

·

CVE-2024-54462

·

Published

2025-01-29

·

Updated

2025-01-29

CVSS v3.1

7.1

High

VectorAV:L/AC:L/PR:N/UI:R/S:U/C:N/I:H/A:H
Name of the Vulnerable Software and Affected Versions image picker versions prior to 0.8.12+18 image picker android versions prior to 0.8.12+18
Description The file names constructed within image picker are missing sanitization checks, leaving them vulnerable to malicious document providers. This may result in cases where a user with a malicious document provider installed can select an image file from that provider while using the app and could potentially override internal files in the app cache.
Recommendations For image picker versions prior to 0.8.12+18, update to the latest version of image picker android that contains the changes to address this issue. For image picker android versions prior to 0.8.12+18, update to version 0.8.12+18 or later to resolve the vulnerability.

Exploit

Fix

Relative Path Traversal

Path traversal

Found an issue in the description? Have something to add? Feel free to write us 👾

Weakness Enumeration

Related Identifiers

CVE-2024-54462
GHSA-98V2-F47X-89XW

Affected Products

Image Picker
Image Picker Android