A Cross Site Scripting vulnerability in LibrePhotos before commit 32237 allows attackers to takeover any account via uploading an HTML file on behalf of the admin user using IDOR in file upload.
Metrics
Affected Vendors & Products
Fixes
Solution
No solution given by the vendor.
Workaround
No workaround given by the vendor.
References
History
Mon, 02 Dec 2024 20:15:00 +0000
Type | Values Removed | Values Added |
---|---|---|
Weaknesses | CWE-639 CWE-79 |
|
Metrics |
cvssV3_1
|
Mon, 02 Dec 2024 18:45:00 +0000
Type | Values Removed | Values Added |
---|---|---|
Description | A Cross Site Scripting vulnerability in LibrePhotos before commit 32237 allows attackers to takeover any account via uploading an HTML file on behalf of the admin user using IDOR in file upload. | |
References |
|

Status: PUBLISHED
Assigner: mitre
Published:
Updated: 2024-12-02T19:23:06.899Z
Reserved: 2024-11-20T00:00:00
Link: CVE-2024-53617

Updated: 2024-12-02T19:22:43.862Z

Status : Received
Published: 2024-12-02T19:15:10.940
Modified: 2024-12-02T20:15:07.710
Link: CVE-2024-53617

No data.

No data.