php-heic-to-jpg < 1.0.5 is vulnerable to remote code execution. An attacker who can upload heic images is able to execute code on the remote server via the file name. As a result, the CIA is no longer guaranteed. This affects php-heic-to-jpg below 1.0.5.
{
"github_reviewed": true,
"cwe_ids": [
"CWE-94"
],
"github_reviewed_at": "2024-10-24T21:45:54Z",
"nvd_published_at": "2024-10-24T18:15:10Z",
"severity": "HIGH"
}