Search Results (2 CVEs found)

CVE Vendors Products Updated CVSS v3.1
CVE-2026-57943 1 Librephotos Project 1 Librephotos 2026-06-29 5.9 Medium
LibrePhotos before 1.0.0 contains a broken object level authorization vulnerability in the SetPhotosShared endpoint that allows authenticated users to grant themselves access to other users' private photos by bypassing ownership validation. Attackers can manipulate shared_to relations without proper owner checks to read arbitrary private photos belonging to other users.
CVE-2023-22903 1 Librephotos Project 1 Librephotos 2025-04-07 9.8 Critical
api/views/user.py in LibrePhotos before e19e539 has incorrect access control.