vendor:
TinyWebGallery
by:
Mirabbas Agalarov
7.5
CVSS
HIGH
RCE
CWE
Product Name: TinyWebGallery
Affected Version From: v2.5
Affected Version To: v2.5
Patch Exists: NO
Related CWE:
CPE:
Platforms Tested: Linux
2023
TinyWebGallery v2.5 – Remote Code Execution (RCE)
The TinyWebGallery v2.5 application is vulnerable to remote code execution (RCE) due to improper handling of uploaded files. An attacker can upload a malicious .phar file containing PHP code and execute arbitrary commands on the server. This can lead to unauthorized access, data theft, or further compromise of the system.
Mitigation:
To mitigate this vulnerability, it is recommended to update TinyWebGallery to the latest version or apply the vendor-supplied patch. Additionally, ensure that file uploads are properly validated and restricted to known file types.