PT-2026-41543 · Kodbox · Filethumb Plugin+1
Vulnplusbot
·
Published
2026-05-17
·
Updated
2026-05-18
·
CVE-2026-8753
CVSS v2.0
6.5
Medium
| Vector | AV:N/AC:L/Au:S/C:P/I:P/A:P |
Name of the Vulnerable Software and Affected Versions
kalcaddle Kodbox versions prior to 1.65
Description
Command injection is possible via remote attack in the fileThumb Plugin. The issue exists within the
parseVideoInfo() function located in the /workspace/source-code/plugins/fileThumb/lib/VideoResize.class.php file, where improper manipulation of the ffmpegBin argument allows for the execution of arbitrary commands.Recommendations
Update to a version later than 1.64.
As a temporary workaround, restrict access to the fileThumb Plugin or the
parseVideoInfo() function to minimize the risk of exploitation.Exploit
Fix
Command Injection
Special Elements Injection
Found an issue in the description? Have something to add? Feel free to write us 👾
Related Identifiers
Affected Products
Kodbox
Filethumb Plugin