Medium
CVSS 4.9
Overview
gif_outputAsJpeg in phpThumb through 1.7.23 allows phpthumb.gif.php OS Command Injection via a crafted parameter value. This is fixed in 1.7.23-202506081709.
gif_outputAsJpeg in phpThumb through 1.7.23 allows phpthumb.gif.php OS Command I...
gif_outputAsJpeg in phpThumb through 1.7.23 allows phpthumb.gif.php OS Command Injection via a crafted parameter value. This is fixed in 1.7.23-202506081709.
This vulnerability is rated 🟡 MEDIUM.
Recommended actions: