What the vulnerability does
01Description
Unauthenticated Broken Access Control in Envira Photo Gallery <= 1.12.5 versions.
CVSS base score
CVSS vector
CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:L/A:L
What the vulnerability does
Unauthenticated Broken Access Control in Envira Photo Gallery <= 1.12.5 versions.
Explanation of Vulnerability in Simple Terms
Envira Photo Gallery versions up to 1.12.5 lack proper authorization checks, allowing unauthenticated attackers to modify or delete gallery data over the network. The vulnerability requires no user interaction and affects the integrity and availability of galleries. Site administrators should update to a version newer than 1.12.5 immediately.
What an attacker can do
Modify or delete photo galleries without authentication.
Potential impact on your site
Galleries can be altered or deleted by anyone on the internet without your permission.
Conditions required to exploit
Network access only; no authentication or user interaction required.
Key dates
External resources
Related vulnerabilities