OS Command Execution through Arbitrary File Upload
Vulnerability Description
If the attacker has access to a valid Poweruser session, remote code execution is possible because specially crafted valid PNG files with injected PHP content can be uploaded as desktop backgrounds or lock screens. After the upload, the PHP script is available in the web root. The PHP code executes once the uploaded file is accessed. This allows the execution of arbitrary PHP code and OS commands on the device as "www-data".
Impact Analysis
Refer to official advisory for detailed impact metrics.
Remediation
Ensure systems are updated to the latest vendor-supplied patch levels.
Am I Vulnerable?
Launch our assessment wizard to check if your infrastructure is exposed to • CVE-2024-47946
Credits & Attribution
The following person or organization is credited with identifying this vulnerability, as recorded in the NVD database:
- Daniel Hirschberger (SEC Consult Vulnerability Lab)
- Tobias Niemann (SEC Consult Vulnerability Lab)
References
Affected Vendor
Image Access GmbH
View all reports →