PT-2026-53662 · Unknown · Librephotos
CVSS v4.0
6.0
Medium
| Vector | AV:N/AC:H/AT:N/PR:L/UI:N/VC:H/VI:L/VA:N/SC:N/SI:N/SA:N |
Name of the Vulnerable Software and Affected Versions
LibrePhotos versions prior to 1.0.0
Description
An issue exists where authenticated users can bypass ownership validation to grant themselves access to private photos belonging to other users. This occurs through the manipulation of
shared to relations within the 'SetPhotosShared' endpoint, allowing the unauthorized reading of arbitrary private photos.Recommendations
Update LibrePhotos to version 1.0.0 or later.
Exploit
Fix
IDOR
Found an issue in the description? Have something to add? Feel free to write us 👾
Weakness Enumeration
Related Identifiers
Affected Products
Librephotos