What the vulnerability does
01Description
Missing Authorization vulnerability in Photo Gallery Team Photo Gallery by 10Web.This issue affects Photo Gallery by 10Web: from n/a through 1.8.25.
CVSS base score
CVSS vector
CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:U/C:N/I:L/A:N
What the vulnerability does
Missing Authorization vulnerability in Photo Gallery Team Photo Gallery by 10Web.This issue affects Photo Gallery by 10Web: from n/a through 1.8.25.
Explanation of Vulnerability in Simple Terms
Photo Gallery by 10Web versions up to 1.8.25 lack proper authorization checks, allowing authenticated users to modify gallery content they should not have access to. An attacker with a low-privilege account can alter gallery data through the plugin's API or interface. The vulnerability affects integrity but not confidentiality or availability. Update to a version newer than 1.8.25.
What an attacker can do
Modify gallery content or settings without proper permission checks.
Potential impact on your site
Unauthorized users can alter or deface gallery content, requiring manual restoration.
Conditions required to exploit
Attacker must have a low-privilege user account on the site.
Key dates
External resources
Related vulnerabilities