9.8
CVE-2025-67079
- EPSS 0.1%
- Veröffentlicht 15.01.2026 00:00:00
- Zuletzt bearbeitet 21.01.2026 14:42:07
- Quelle cve@mitre.org
- CVE-Watchlists
- Unerledigt
File upload vulnerability in Omnispace Agora Project before 25.10 allowing attackers to execute code through the MSL engine of the Imagick library via crafted PDF file to the file upload and thumbnail functions.
Daten sind bereitgestellt durch National Vulnerability Database (NVD)
Agora-project ≫ Agora-project Version < 25.10
| Typ | Quelle | Score | Percentile |
|---|---|---|---|
| EPSS | FIRST.org | 0.1% | 0.278 |
| Quelle | Base Score | Exploit Score | Impact Score | Vector String |
|---|---|---|---|---|
| 134c704f-9b21-4f2e-91b3-4a467353bcc0 | 9.8 | 3.9 | 5.9 |
CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H
|
CWE-434 Unrestricted Upload of File with Dangerous Type
The product allows the upload or transfer of dangerous file types that are automatically processed within its environment.