PT-2025-29244 · Phpthumb · Phpthumb

Kamil Szczurowski

+1

·

Published

2025-07-11

·

Updated

2025-07-14

·

CVE-2025-52994

CVSS v3.1

4.9

Medium

VectorAV:N/AC:H/PR:L/UI:N/S:C/C:L/I:L/A:N
Name of the Vulnerable Software and Affected Versions: phpThumb versions through 1.7.23
Description: The gif outputAsJpeg function in phpThumb through version 1.7.23 allows for OS Command Injection via a crafted parameter value in phpthumb.gif.php. This issue is addressed in version 1.7.23-202506081709.
Recommendations: Update to phpThumb version 1.7.23-202506081709 or later.

Fix

OS Command Injection

Weakness Enumeration

Related Identifiers

CVE-2025-52994
GHSA-Q745-CFQH-HCRW

Affected Products

Phpthumb