Skip to content

Insufficient checking of uploaded files

High
m1k1o published GHSA-wmqj-5v54-24x4 Jan 6, 2022

Package

No package listed

Affected versions

<1.3

Patched versions

1.4

Description

Errors from functions imagecreatefrom* and image* have not been checked properly. Although PHP issued warning and function returned false, original file (that could contain malicious payload) was kept on the disk.

Impact

All versions until v1.3.

Patches

Users should upgrade to v1.4.

Severity

High

CVE ID

CVE-2022-23626

Weaknesses

Credits