Agora Project
cpe:2.3:a:agora-project:agora-project:*:*:*:*:*:*:*
- <= v25.6.4
A file upload vulnerability has been identified in the Omnispace Agora Project, affecting versions prior to 25.10. This vulnerability allows attackers to execute code through the MSL engine of the Imagick library. The issue arises from the improper handling of PDF files uploaded via the file upload and thumbnail functions.
Exploitation of this vulnerability allows for arbitrary code execution on the server.
To reproduce this vulnerability, upload a crafted PDF file that exploits the Imagick library's MSL engine. Once the file is uploaded, the thumbnail generation process will trigger the execution of the embedded PHP code.
Users are advised to update to version 25.10 or later. Additionally, ImageMagick should be configured to disable MSL execution by adding a policy rule that denies all rights to the MSL coder.
Our algorithm analyzes dozens of metrics to generate these 8 key vulnerability categories, which are then combined to calculate the overall risk score.