Description
A Cross Site Scripting vulnerability in LibrePhotos before commit 32237 allows attackers to takeover any account via uploading an HTML file on behalf of the admin user using IDOR in file upload.
No analysis available yet.
Remediation
No remediation available yet.
Tracking
Sign in to view the affected projects.
Advisories
| Source | ID | Title |
|---|---|---|
EUVD |
EUVD-2024-52011 | A Cross Site Scripting vulnerability in LibrePhotos before commit 32237 allows attackers to takeover any account via uploading an HTML file on behalf of the admin user using IDOR in file upload. |
References
History
Mon, 02 Dec 2024 20:15:00 +0000
| Type | Values Removed | Values Added |
|---|---|---|
| Weaknesses | CWE-639 CWE-79 |
|
| Metrics |
cvssV3_1
|
Mon, 02 Dec 2024 18:45:00 +0000
| Type | Values Removed | Values Added |
|---|---|---|
| Description | A Cross Site Scripting vulnerability in LibrePhotos before commit 32237 allows attackers to takeover any account via uploading an HTML file on behalf of the admin user using IDOR in file upload. | |
| References |
|
Subscriptions
No data.
Status: PUBLISHED
Assigner: mitre
Published:
Updated: 2024-12-02T19:23:06.899Z
Reserved: 2024-11-20T00:00:00.000Z
Link: CVE-2024-53617
Updated: 2024-12-02T19:22:43.862Z
Status : Received
Published: 2024-12-02T19:15:10.940
Modified: 2024-12-02T20:15:07.710
Link: CVE-2024-53617
No data.
OpenCVE Enrichment
No data.
EUVD