Impact
The vulnerability allows attackers to inject arbitrary SQL into the album_id path segment of the download route, enabling them to retrieve sensitive data from the database through time‑based or blind techniques. This grants read access to potentially all information stored in the database and can facilitate further attacks if additional system data is exposed.
Affected Systems
All installations of Photoview up to and including version 2.4.0 are affected. The web gallery application exposes the vulnerable download endpoint to anyone who can reach the site; the flaw does not require authentication and can be exploited remotely.
Risk and Exploitability
The CVSS score of 8.7 indicates high severity. EPSS information is not provided, but the vulnerability allows unauthenticated, remote attackers to craft a single HTTP request to the download route and extract data without special conditions. While no public exploit is listed, the straightforward nature of the attack makes it a viable target for automated scanners.
OpenCVE Enrichment