CVE-2024-57407

High severity, CVSS 7.3. EPSS: 0.4% chance of exploitation in the next 30 days.

An arbitrary file upload vulnerability in the component /userPicture of Timo v2.0.3 allows attackers to execute arbitrary code via uploading a crafted file.

Published 2025-02-10. Last modified 2026-06-17.