Impact
A vulnerability exists in the Media File Preview Plugin of kalcaddle kodbox in the VideoResize class. The localFile argument can be manipulated to bypass input validation and trigger arbitrary operating‑system commands through the run function. This allows an attacker to execute commands on the server hosting the plugin. The flaw is classified by CWE‑77 and CWE‑78.
Affected Systems
This vulnerability affects kalcaddle kodbox versions up to 1.64.05 that include the Media File Preview Plugin. Any installation containing plugins/fileThumb/lib/VideoResize.class.php is potentially vulnerable.
Risk and Exploitability
The CVSS base score of 5.3 indicates a medium severity level. The EPSS score of 1% suggests the likelihood of exploitation is low in the general population. The vulnerability is not listed in CISA’s KEV catalog. The exploit is remote, requiring only a crafted localFile parameter to invoke operating‑system commands.
OpenCVE Enrichment