Joomla 扩展 - svenbluege.de - Event Gallery 扩展(版本低于 6.6.0)中的 Google 照片选择器存在服务器端请求伪造(SSRF)漏洞。后端上传页面的 Google 照片选择器在选取图像时,会通过服务器使用 Google Photos 账户的 OAuth 访问令牌来获取所选中图像的缩略图。该功能未对请求中指定的目标地址进行验证,且未要求提供表单令牌。因此,攻击者可利用其他网站上的预构造页面,诱使服务器以已登录管理员的身份将账户的访问令牌发送到任意地址,或访问服务器内部网络
Although we use advanced large model technology, its output may still contain inaccurate or outdated information.Shenlong tries to ensure data accuracy, but please verify and judge based on the actual situation.
| Vendor | Product | Affected Versions | CPE | Subscribe |
|---|---|---|---|---|
| svenbluege.de | Event Gallery for Joomla | 1.0.0-6.6.0 | - |
|
| # | POC Description | Source Link | Shenlong Link |
|---|
No public POC found.
Login to generate AI POC| CVE-2026-102778 | 5.3 MEDIUM | Joomla Extension - svenbluege.de - Cross-site scripting and open redirect on the share min |
| CVE-2026-102776 | 5.1 MEDIUM | Joomla Extension - svenbluege.de - Cross-site request forgery of list tasks of the backend |
No comments yet