Vulnerability Information
Although we use advanced large model technology, its output may still contain inaccurate or outdated information.Shenlong tries to ensure data accuracy, but please verify and judge based on the actual situation.
Vulnerability Title
LibrePhotos < 1.0.0 - Insecure Direct Object Reference in SetPhotosShared Endpoint
Vulnerability Description
LibrePhotos before 1.0.0 contains a broken object level authorization vulnerability in the SetPhotosShared endpoint that allows authenticated users to grant themselves access to other users' private photos by bypassing ownership validation. Attackers can manipulate shared_to relations without proper owner checks to read arbitrary private photos belonging to other users.
CVSS Information
CVSS:3.1/AV:N/AC:H/PR:L/UI:N/S:U/C:H/I:L/A:N
Vulnerability Type
通过用户控制密钥绕过授权机制
Vulnerability Title
LibrePhotos 授权问题漏洞
Vulnerability Description
LibrePhotos是LibrePhotos团队开源的一个自托管开源照片管理服务。 LibrePhotos 1.0.0之前版本存在授权问题漏洞,该漏洞源于SetPhotosShared端点存在损坏的对象级授权问题,允许经过身份验证的用户通过绕过所有权验证来访问其他用户的私有照片,攻击者可操纵shared_to关系而无需适当的所有者检查来读取其他用户的任意私有照片。
CVSS Information
N/A
Vulnerability Type
N/A