← Back

Photoshow

photoshow

Vendor: Thibaud Rohmer • 1 CVE

CVEs (1)

CVE
VENDORS
PRODUCTS
UPDATED
PUBLISHED
CVSS
1Thibaud Rohmer
1Photoshow
Dec 27, 2025
Dec 22, 2025
8.6 HIGH· v4
7.2 HIGH· v3
N/A· v2
PhotoShow 3.0 contains a remote code execution vulnerability that allows authenticated administrators to inject malicious commands through the exiftran path configuration. Attackers can exploit the ffmpeg configuration s...Show more
PhotoShow 3.0 contains a remote code execution vulnerability that allows authenticated administrators to inject malicious commands through the exiftran path configuration. Attackers can exploit the ffmpeg configuration settings by base64 encoding a reverse shell command and executing it through a crafted video upload process.Show less