Impact
Elgg versions before 7.0.0 allow avatars to be uploaded without validating image dimensions, which enables an attacker to submit a file of extreme size and exhaust server memory while processing it. The resulting resource exhaustion forces the application to become unresponsive, causing a denial of service problem. The weakness is identified as a resource abuse flaw (CWE-770). The likely attack vector is via the avatar upload feature, which requires an authenticated user account.
Affected Systems
All installations of Elgg older than version 7.0.0 are affected.
Risk and Exploitability
The CVSS score of 4.3 indicates low severity, while the EPSS score below 1% reflects a very low probability of exploitation. The vulnerability is not included in CISA KEV. The likely attack vector is an authenticated user accessing the avatar upload feature, as the upload capability typically requires login. Even though the threat is low, large image uploads could still lead to memory exhaustion and service interruption.
OpenCVE Enrichment