Goal Reached Thanks to every supporter — we hit 100%!

Goal: 1000 CNY · Raised: 1359 CNY

100%

CVE-2026-102777— Joomla Extension - svenbluege.de - Server-side request forgery in the Google Photos picker in Event Gallery extension < 6.6.0

Quick assessment

Affected
svenbluege.de Event Gallery for Joomla
Exploitation
No confirmed in-the-wild exploitation; assess based on exposure
Recommended action
Check the vendor advisory and references for a fixed version. If immediate upgrade is impossible, restrict exposure and increase monitoring.

Joomla 扩展 - svenbluege.de - Event Gallery 扩展(版本低于 6.6.0)中的 Google 照片选择器存在服务器端请求伪造(SSRF)漏洞。后端上传页面的 Google 照片选择器在选取图像时,会通过服务器使用 Google Photos 账户的 OAuth 访问令牌来获取所选中图像的缩略图。该功能未对请求中指定的目标地址进行验证,且未要求提供表单令牌。因此,攻击者可利用其他网站上的预构造页面,诱使服务器以已登录管理员的身份将账户的访问令牌发送到任意地址,或访问服务器内部网络

CVSS 6.3 · Medium
Get alerts for future matching vulnerabilities Log in to subscribe

I. Basic Information for CVE-2026-102777

Vulnerability Information

Have questions about the vulnerability? See if Shenlong's analysis helps!
View Shenlong Deep Dive ↗

Although we use advanced large model technology, its output may still contain inaccurate or outdated information.Shenlong tries to ensure data accuracy, but please verify and judge based on the actual situation.

Vulnerability Title
Joomla Extension - svenbluege.de - Server-side request forgery in the Google Photos picker in Event Gallery extension < 6.6.0
Source: CVE Program / CVE List V5
Vulnerability Description
Joomla Extension - svenbluege.de - Server-side request forgery in the Google Photos picker in Event Gallery extension < 6.6.0 - The Google Photos picker of the back-end upload page fetches the thumbnails of the picked images through the server, with the OAuth access token of the Google Photos account. The task took the address to fetch from the request without checking it and asked for no form token. A prepared page on another web site could therefore make the server send the access token of the account to any address, or fetch addresses inside the server's network, in the name of a logged in administrator; a back-end user with the permission "Manage" could do the same directly. The token is valid for about an hour and reaches what the picker session of the account reaches.
Source: CVE Program / CVE List V5
CVSS Information
CVSS:4.0/AV:N/AC:L/AT:N/PR:N/UI:A/VC:L/VI:N/VA:N/SC:H/SI:L/SA:L
Source: CVE Program / CVE List V5
Vulnerability Type
服务端请求伪造(SSRF)
Source: CVE Program / CVE List V5

Affected Products

Vendor Product Affected Versions CPE Subscribe
svenbluege.de Event Gallery for Joomla 1.0.0-6.6.0 -

II. Public POCs for CVE-2026-102777

# POC Description Source Link Shenlong Link
AI-Generated POC Premium

No public POC found.

Login to generate AI POC

III. Intelligence Information for CVE-2026-102777

请登录查看更多情报信息。

Other References for CVE-2026-102777 (1)

Same Patch Batch · svenbluege.de · 2026-10-05 · 3 CVEs total

CVE-2026-102778 5.3 MEDIUM Joomla Extension - svenbluege.de - Cross-site scripting and open redirect on the share min
CVE-2026-102776 5.1 MEDIUM Joomla Extension - svenbluege.de - Cross-site request forgery of list tasks of the backend

IV. Related Vulnerabilities

V. Comments for CVE-2026-102777

No comments yet


Leave a comment