Direct naar de inhoud
⚡ Kritieke cyberalerts voor jouw sector & systemen — direct in je inbox. Aanmelden →
CVE's Videos Dagbriefing

← Terug naar CVE-database

CVE-2026-96673

HIGH · 7.5 CVSS Gepubliceerd: CWE-89

Beschrijving NL

Photoview via 2.4.0 bevat een kwetsbaarheid voor SQL-injectie in de downloadroute van het album waarmee niet-geverifieerde aanvallers SQL kunnen injecteren door het album_id-padsegment te manipuleren. Aanvallers kunnen vervaardigde SQL-expressies leveren in de parameter album_id om willekeurige gegevens uit de database te extraheren met behulp van op tijd gebaseerde of blinde injectietechnieken.

Origineel (Engels) tonen

Photoview through 2.4.0 contains an SQL injection vulnerability in the album download route that allows unauthenticated attackers to inject SQL by manipulating the album_id path segment. Attackers can supply crafted SQL expressions in the album_id parameter to extract arbitrary data from the database using time-based or blind injection techniques.

References