LIVE · cybersecurity feed
Live wire
cve recordhigh

CVE-2026-48997

Published
CVSS7.1
Severityhigh
WeaknessCWE-78
ExploitedNot in CISA KEV

CVSS:3.1/AV:N/AC:H/PR:L/UI:N/S:U/C:L/I:H/A:H

Description

e107 is a content management system (CMS). Versions 2.3.5 and earlier contain a command injection vulnerability in the ImageMagick resize destination path. In resize_image(), the source path is escaped with escapeshellarg(), but the destination path is inserted inside raw double quotes in the convert command; in the submit-news upload flow, that destination filename includes the first six characters of user-controlled news title input. Because the title filter removes literal spaces but not tab characters, and shell expansions such as $(...) and backticks can survive into the quoted destination argument, /bin/sh -c may evaluate attacker-controlled input. Exploitation is possible only when a

References

← Back to the CVE Tracker

Our coverage of CVE-2026-48997

No stories yet. This page updates automatically when we publish reporting that references CVE-2026-48997.