Lucene search

K
veracodeVeracode Vulnerability DatabaseVERACODE:12047
HistoryJan 15, 2019 - 9:11 a.m.

Remote Code Execution (RCE)

2019-01-1509:11:36
Veracode Vulnerability Database
sca.analysiscenter.veracode.com
11

0.967 High

EPSS

Percentile

99.7%

ImageMagick is vulnerable to remote code execution (RCE). The library does not sanitize certain user inputs, allowing a malicious user to pass a malicious image to the system for file conversion to trigger the execution of arbitrary code. This is also known as the ImageTragick vulnerability.

References