Impact
ExifTool for photo and video 5.0.1-gms builds shell commands from media file paths and executes them through /system/bin/sh without adequate escape of single quotes entered in filenames. If an attacker can a malicious filename, they can inject arbitrary shell commands into the constructed command string. The consequence is that the attacker can run any command with the privileges of the application, potentially compromising data integrity and availability on the affected device.
Affected Systems
The vulnerability affects CellHubs ExifTool for photo and video version 5.0.1-gms for Android.
Risk and Exploitability
The CVSS score of 8.4 indicates a high severity of this flaw, and the EPSS score is presently not available, which does not indicate a known prevalence yet. The vulnerability is not yet listed in the CISA KEV catalog. The likely attack vector is local file manipulation; an attacker who can create or rename a file that the application will process during CSV export can execute arbitrary system commands on the device.
OpenCVE Enrichment