Vulnerabilities/

files.photo.gallery command injection

Severity:
Medium

Description

A command injection vulnerability in the video thumbnail rendering component of files.photo.gallery v0.3.0 through 0.11.0 allows remote attackers to execute arbitrary code via a crafted video file.

Recommendation

No fix is available yet. Followings are affected versions:

References

Related Issues

Tags:
npm
files.photo.gallery
Anything's wrong? Let us know Last updated on February 06, 2025

This issue is available in SmartScanner Professional

See Pricing