CVE-2016-3718

MEDIUM5.5⚠ KEVEPSS 86.9%

ImageMagick Server-Side Request Forgery (SSRF) Vulnerability

Published: 5/5/2016Modified: 4/28/2026Added to CISA KEV: 11/3/2021

Description

The (1) HTTP and (2) FTP coders in ImageMagick before 6.9.3-10 and 7.x before 7.0.1-1 allow remote attackers to conduct server-side request forgery (SSRF) attacks via a crafted image.

Affected packages (2)

CVSS scores

SourceVersionSeverityVector
osvCVSS 3.1MEDIUM5.5CVSS:3.1/AV:L/AC:L/PR:N/UI:R/S:U/C:N/I:H/A:N

References (1)