PT-2026-50553 · Imagemagick+1 · Imagemagick+1

·

CVE-2026-48997

·

Published

2026-06-17

·

Updated

2026-06-17

CVSS v3.1

7.1

High

VectorAV:N/AC:H/PR:L/UI:N/S:U/C:L/I:H/A:H
Name of the Vulnerable Software and Affected Versions e107 versions prior to 2.3.6
Description e107 is a content management system (CMS) that contains a command injection issue in the ImageMagick resize destination path. Within the resize image() function, the source path is properly escaped, but the destination path is inserted into raw double quotes in the convert command. In the submit-news upload flow, the destination filename incorporates the first six characters of the user-controlled news title input. Since the title filter removes literal spaces but not tab characters, shell expansions such as $(...) and backticks can persist in the quoted destination argument, allowing /bin/sh -c to evaluate attacker-controlled input.
Exploitation requires the following non-default settings to be enabled:
  • resize method set to ImageMagick
  • subnews attach set to 1
  • upload enabled set to 1
  • subnews resize as a numeric value between 30 and 5000
  • The attacker must be a non-admin in classes permitted by both subnews class and upload class.
Recommendations Update to version 2.3.6.

Exploit

Fix

OS Command Injection

Found an issue in the description? Have something to add? Feel free to write us 👾

Weakness Enumeration

Related Identifiers

CVE-2026-48997
GHSA-3J33-C9V4-4P42

Affected Products

Imagemagick
E107