CVE-2026-8753 PUBLISHED

kalcaddle Kodbox fileThumb Plugin VideoResize.class.php parseVideoInfo command injection

Assigner: VulDB
Reserved: 16.05.2026 Published: 17.05.2026 Updated: 17.05.2026

A security vulnerability has been detected in kalcaddle Kodbox up to 1.64. This issue affects the function parseVideoInfo of the file /workspace/source-code/plugins/fileThumb/lib/VideoResize.class.php of the component fileThumb Plugin. The manipulation of the argument ffmpegBin leads to command injection. It is possible to initiate the attack remotely. The exploit has been disclosed publicly and may be used. The vendor was contacted early about this disclosure but did not respond in any way.

Metrics

CVSS Vector: CVSS:4.0/AV:N/AC:L/AT:N/PR:L/UI:N/VC:L/VI:L/VA:L/SC:N/SI:N/SA:N/E:P
CVSS Score: 5.3

Product Status

Vendor kalcaddle
Product Kodbox
Versions
  • Version 1.0 is affected
  • Version 1.1 is affected
  • Version 1.2 is affected
  • Version 1.3 is affected
  • Version 1.4 is affected
  • Version 1.5 is affected
  • Version 1.6 is affected
  • Version 1.7 is affected
  • Version 1.8 is affected
  • Version 1.9 is affected
  • Version 1.10 is affected
  • Version 1.11 is affected
  • Version 1.12 is affected
  • Version 1.13 is affected
  • Version 1.14 is affected
  • Version 1.15 is affected
  • Version 1.16 is affected
  • Version 1.17 is affected
  • Version 1.18 is affected
  • Version 1.19 is affected
  • Version 1.20 is affected
  • Version 1.21 is affected
  • Version 1.22 is affected
  • Version 1.23 is affected
  • Version 1.24 is affected
  • Version 1.25 is affected
  • Version 1.26 is affected
  • Version 1.27 is affected
  • Version 1.28 is affected
  • Version 1.29 is affected
  • Version 1.30 is affected
  • Version 1.31 is affected
  • Version 1.32 is affected
  • Version 1.33 is affected
  • Version 1.34 is affected
  • Version 1.35 is affected
  • Version 1.36 is affected
  • Version 1.37 is affected
  • Version 1.38 is affected
  • Version 1.39 is affected
  • Version 1.40 is affected
  • Version 1.41 is affected
  • Version 1.42 is affected
  • Version 1.43 is affected
  • Version 1.44 is affected
  • Version 1.45 is affected
  • Version 1.46 is affected
  • Version 1.47 is affected
  • Version 1.48 is affected
  • Version 1.49 is affected
  • Version 1.50 is affected
  • Version 1.51 is affected
  • Version 1.52 is affected
  • Version 1.53 is affected
  • Version 1.54 is affected
  • Version 1.55 is affected
  • Version 1.56 is affected
  • Version 1.57 is affected
  • Version 1.58 is affected
  • Version 1.59 is affected
  • Version 1.60 is affected
  • Version 1.61 is affected
  • Version 1.62 is affected
  • Version 1.63 is affected
  • Version 1.64 is affected

Credits

  • vulnplusbot (VulDB User) reporter
  • VulDB CNA Team coordinator

References

Problem Types

  • Command Injection CWE
  • Injection CWE