PT-2025-3026 · Unknown · Image Picker Android+1
Oskar-Zeinomahmalat-Sonarsource
·
Published
2025-01-29
·
Updated
2025-01-29
·
CVE-2024-54462
CVSS v3.1
7.1
High
| Vector | AV:L/AC:L/PR:N/UI:R/S:U/C:N/I:H/A:H |
Name of the Vulnerable Software and Affected Versions
image picker versions prior to 0.8.12+18
image picker android versions prior to 0.8.12+18
Description
The file names constructed within image picker are missing sanitization checks, leaving them vulnerable to malicious document providers. This may result in cases where a user with a malicious document provider installed can select an image file from that provider while using the app and could potentially override internal files in the app cache.
Recommendations
For image picker versions prior to 0.8.12+18, update to the latest version of image picker android that contains the changes to address this issue.
For image picker android versions prior to 0.8.12+18, update to version 0.8.12+18 or later to resolve the vulnerability.
Fix
Path traversal
Relative Path Traversal
Found an issue in the description? Have something to add? Feel free to write us 👾
Related Identifiers
Affected Products
Image Picker
Image Picker Android