CVE-2024-53615

Severity CVSS v4.0:
Pending analysis
Type:
CWE-77 Command Injection
Publication date:
30/01/2025
Last modified:
06/02/2025

Description

A command injection vulnerability in the video thumbnail rendering component of Karl Ward's files.gallery v0.3.0 through 0.11.0 allows remote attackers to execute arbitrary code via a crafted video file.

References to Advisories, Solutions, and Tools