PT-2026-56237 · Chevereto · Chevereto
CVSS v4.0
6.9
Medium
| Vector | AV:N/AC:L/AT:N/PR:N/UI:N/VC:L/VI:N/VA:N/SC:N/SI:N/SA:N/E:X/CR:X/IR:X/AR:X/MAV:X/MAC:X/MAT:X/MPR:X/MUI:X/MVC:X/MVI:X/MVA:X/MSC:X/MSI:X/MSA:X/S:X/AU:X/R:X/V:X/RE:X/U:X |
Name of the Vulnerable Software and Affected Versions
Chevereto versions 3.7.5 through 4.5.3
Description
An issue exists in the self-hosted media-sharing platform where the
/json AJAX listing endpoint fails to enforce private profile restrictions. While the profile HTML route (/username) correctly returns a 404 error for private profiles, the /json endpoint allows an unauthenticated caller with a target user ID to retrieve all publicly-scoped images, which subsequently reveals the private username.Recommendations
Update to version 4.5.4.
Exploit
Fix
Missing Authorization
Found an issue in the description? Have something to add? Feel free to write us 👾
Weakness Enumeration
Related Identifiers
Affected Products
Chevereto