modules/gallery/helpers/data_rest.php in Gallery 3 before 3.0.9 allows remote attackers to bypass intended access restrictions and obtain sensitive information (image files) via the "full" string in the size parameter.
Exploit prediction scoring system (EPSS) score
EPSS Score 0.016
EPSS Ranking 72.1%