PT-2026-50553 · Imagemagick+1 · Imagemagick+1
CVSS v3.1
7.1
High
| Vector | AV:N/AC:H/PR:L/UI:N/S:U/C:L/I:H/A:H |
Name of the Vulnerable Software and Affected Versions
e107 versions prior to 2.3.6
Description
e107 is a content management system (CMS) that contains a command injection issue in the ImageMagick resize destination path. Within the
resize image() function, the source path is properly escaped, but the destination path is inserted into raw double quotes in the convert command. In the submit-news upload flow, the destination filename incorporates the first six characters of the user-controlled news title input. Since the title filter removes literal spaces but not tab characters, shell expansions such as $(...) and backticks can persist in the quoted destination argument, allowing /bin/sh -c to evaluate attacker-controlled input.Exploitation requires the following non-default settings to be enabled:
resize methodset to ImageMagicksubnews attachset to 1upload enabledset to 1subnews resizeas a numeric value between 30 and 5000- The attacker must be a non-admin in classes permitted by both
subnews classandupload class.
Recommendations
Update to version 2.3.6.
Exploit
Fix
OS Command Injection
Found an issue in the description? Have something to add? Feel free to write us 👾
Weakness Enumeration
Related Identifiers
Affected Products
Imagemagick
E107