PT-2026-63541 · Drupal+2 · Photoswipe - Responsive Javascript Modal Image Gallery+2
CVSS v3.1
9.1
Critical
| Vector | AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:N |
Name of the Vulnerable Software and Affected Versions
PhotoSwipe - Responsive JavaScript Modal Image Gallery versions 0.0.0 through 3.2.0
Description
A missing authorization issue allows forceful browsing when viewing images using the photoswipe image gallery display formatter. The module fails to sufficiently check access permissions, which may allow unauthorized users to view images that should be restricted.
Recommendations
Update PhotoSwipe - Responsive JavaScript Modal Image Gallery to version 3.0.4 or later for Drupal 8.
Update PhotoSwipe - Responsive JavaScript Modal Image Gallery to version 3.2.0 or later for Drupal 9 and Drupal 10.
Exploit
Fix
Missing Authorization
Found an issue in the description? Have something to add? Feel free to write us 👾
Weakness Enumeration
Related Identifiers
Affected Products
Photoswipe - Responsive Javascript Modal Image Gallery
Drupal/Photoswipe
Photoswipe