The URL rewrite module in Menalto Gallery before 2.2.4 allows attackers to include and execute arbitrary local files via unknown vectors related to the admin controller.
Exploit prediction scoring system (EPSS) score
EPSS Score 0.016
EPSS Ranking 72.1%