Joomla 扩展 - svenbluege.de - Event Gallery 扩展版本低于 6.6.0 的管理端列表任务存在跨站请求伪造(CSRF)漏洞。后端列表按钮所触发的八个任务未验证表单令牌(form token):包括设置默认支付方式、配送方式、图像类型、订单状态和水印;将事件添加至商店或从商店移除;选择事件的主图像以及设置图像是否仅作为主图像显示;以及对事件图像的排序。攻击者可通过在其他网站预构造的页面,以已登录管理员的身份触发这些操作,从而更改相关设置和标志位。此漏洞无法用于删除或读取任何数据,且
Although we use advanced large model technology, its output may still contain inaccurate or outdated information.Shenlong tries to ensure data accuracy, but please verify and judge based on the actual situation.
| Vendor | Product | Affected Versions | CPE | Subscribe |
|---|---|---|---|---|
| svenbluege.de | Event Gallery for Joomla | 1.0.0-6.6.0 | - |
|
| # | POC Description | Source Link | Shenlong Link |
|---|
No public POC found.
Login to generate AI POC| CVE-2026-102777 | 6.3 MEDIUM | Joomla Extension - svenbluege.de - Server-side request forgery in the Google Photos picker |
| CVE-2026-102778 | 5.3 MEDIUM | Joomla Extension - svenbluege.de - Cross-site scripting and open redirect on the share min |
No comments yet