CyberRota Analysis
AI-GeneratedPiwigo versions prior to 16.4.0 are vulnerable to arbitrary file read and remote code execution due to inadequate validation of user-uploaded images when using the Imagick library. Attackers can exploit this vulnerability by disguising malicious SVG content as PNG files, leading to unauthorized access and potential server-side file manipulation. Organizations using Piwigo should prioritize patching to version 16.4.0 to mitigate these risks.
Public Exploit Signal
A public exploit, PoC, GitHub repository or Metasploit reference was detected for this CVE.
Note: these links are listed for security research and verification purposes only.
Original NVD Description
Piwigo before v16.4.0 is vulnerable to arbitrary file read and remote code execution in image upload handling when using the Imagick library due to insufficient validation and unsafe processing of user-supplied image files. By abusing format confusion (e.g., disguising SVG content as PNG), an attacker can trigger unintended interpretation of embedded SVG elements that reference local files. In more advanced scenarios, the Imagick support for Magick Scripting Language (MSL) may be abused to process attacker-controlled instructions, potentially leading to unauthorized server-side file writes and remote code execution, depending on configuration. This has been patched in 16.4.0.