Photoview · Photoview · CVE-2026-96673
**Name of the Vulnerable Software and Affected Versions**
Photoview versions prior to 2.4.1
**Description**
An SQL injection issue exists in the album download route. Unauthenticated attackers can inject SQL by manipulating the `album id` path segment. By supplying crafted SQL expressions in the `album id` parameter, attackers can extract arbitrary data from the database using time-based or blind injection techniques. Time-based injection is a method where the attacker sends a query that forces the database to wait a specific amount of time before responding if a condition is true, while blind injection involves asking the database true/false questions to infer data.
**Recommendations**
Update Photoview to a version newer than 2.4.0.
Avoid using the `album id` parameter in the album download route until the issue is resolved.