What the vulnerability does
01Description
Contributor Arbitrary File Deletion in Picture Gallery <= 1.6.5 versions.
CVSS base score
CVSS vector
CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:U/C:N/I:L/A:H
What the vulnerability does
Contributor Arbitrary File Deletion in Picture Gallery <= 1.6.5 versions.
Explanation of Vulnerability in Simple Terms
Picture Gallery versions up to 1.6.5 contain a path traversal vulnerability that allows authenticated users to manipulate file paths and corrupt or delete files on the server. An attacker with low-level access can bypass directory restrictions to write or delete arbitrary files, potentially disabling the site or modifying critical data. No confidentiality impact occurs, but integrity and availability are severely compromised.
What an attacker can do
Write or delete files outside the intended gallery directory, disrupting site functionality or data.
Potential impact on your site
Malicious users can corrupt or delete files, causing data loss or site downtime without admin intervention.
Conditions required to exploit
Attacker must have a low-privilege user account on the site; no user interaction required.
Key dates
External resources
Related vulnerabilities