PT-2026-84294 · Fs Poster · Fs Poster
CVSS v3.1
8.8
High
| Vector | AV:N/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H |
Name of the Vulnerable Software and Affected Versions
FS-Poster versions prior to 8.0.2
Description
Insufficient input sanitization of the
FFmpeg path parameter before it is passed to the exec() function, combined with missing authorization checks on REST API endpoints, allows authenticated attackers with subscriber-level access or higher to execute arbitrary commands on the server. Remote Code Execution refers to the ability of an attacker to run any command of their choice on a target machine.Recommendations
Update FS-Poster to a version newer than 8.0.1.
Restrict access to the REST API endpoints used for FFmpeg path configuration to minimize the risk of exploitation.
Fix
RCE
Command Injection
Found an issue in the description? Have something to add? Feel free to write us 👾
Weakness Enumeration
Related Identifiers
Affected Products
Fs Poster