CVE-2025-52994
EUVD-2025-2115411.07.2025, 15:15
gif_outputAsJpeg in phpThumb through 1.7.23 allows phpthumb.gif.php OS Command Injection via a crafted parameter value. This is fixed in 1.7.23-202506081709.
Early Detection
Affected products identified ahead of NVD analysis through intelligence sources.
| Vendor | Product | Version | Source |
|---|---|---|---|
| phpthumb_project | phpthumb | 𝑥 ≤ 1.7.23 | CNA |