PT-2026-97122 · Photoview · Photoview
CVSS v3.1
7.1
High
| Vector | AV:N/AC:L/PR:L/UI:N/S:U/C:H/I:L/A:N |
Name of the Vulnerable Software and Affected Versions
Photoview versions prior to 2.4.1
Description
An authorization bypass exists in the
shareAlbum GraphQL mutation. This flaw allows authenticated users to generate share tokens for albums they do not own by providing arbitrary album IDs. Consequently, photos and sub-albums are exposed to anyone possessing the link, and the attacker maintains indefinite control over the token settings.Recommendations
Update Photoview to version 2.4.1 or later.
As a temporary mitigation, restrict access to the
shareAlbum GraphQL mutation.Fix
IDOR
Found an issue in the description? Have something to add? Feel free to write us 👾
Weakness Enumeration
Related Identifiers
Affected Products
Photoview