Home
Home
Trends
Trends
Vulnerabilities
Vulnerabilities
News
News
Researchers
Researchers
Why dbugs?
Why dbugs?
Settings

Fedek-Xbow

#37523of 57,427
7.5Total CVSS
Vulnerabilities · 1
PT-2026-97359
7.5
2026-09-23
Photoview · Photoview · CVE-2026-96673
**Name of the Vulnerable Software and Affected Versions** Photoview versions prior to 2.4.1 **Description** An SQL injection issue exists in the album download route. Unauthenticated attackers can inject SQL by manipulating the `album id` path segment. By supplying crafted SQL expressions in the `album id` parameter, attackers can extract arbitrary data from the database using time-based or blind injection techniques. Time-based injection is a method where the attacker sends a query that forces the database to wait a specific amount of time before responding if a condition is true, while blind injection involves asking the database true/false questions to infer data. **Recommendations** Update Photoview to a version newer than 2.4.0. Avoid using the `album id` parameter in the album download route until the issue is resolved.