A Cross Site Scripting vulnerability in LibrePhotos before commit 32237 allows attackers to takeover any account via uploading an HTML file on behalf of the admin user using IDOR in file upload.
History

Mon, 02 Dec 2024 20:15:00 +0000

Type Values Removed Values Added
Weaknesses CWE-639
CWE-79
Metrics cvssV3_1

{'score': 4.8, 'vector': 'CVSS:3.1/AV:N/AC:L/PR:H/UI:R/S:C/C:L/I:L/A:N'}

ssvc

{'options': {'Automatable': 'no', 'Exploitation': 'none', 'Technical Impact': 'partial'}, 'version': '2.0.3'}


Mon, 02 Dec 2024 18:45:00 +0000

Type Values Removed Values Added
Description A Cross Site Scripting vulnerability in LibrePhotos before commit 32237 allows attackers to takeover any account via uploading an HTML file on behalf of the admin user using IDOR in file upload.
References

cve-icon MITRE

Status: PUBLISHED

Assigner: mitre

Published: 2024-12-02T00:00:00

Updated: 2024-12-02T19:23:06.899Z

Reserved: 2024-11-20T00:00:00

Link: CVE-2024-53617

cve-icon Vulnrichment

Updated: 2024-12-02T19:22:43.862Z

cve-icon NVD

Status : Received

Published: 2024-12-02T19:15:10.940

Modified: 2024-12-02T20:15:07.710

Link: CVE-2024-53617

cve-icon Redhat

No data.