Vulnerabilities
Vulnerable Software
Lycheeorg:  >> Lychee  Security Vulnerabilities
Cross-site Request Forgery (CSRF) vulnerability in Lychee version 3.1.6, allows remote attackers to execute arbitrary code via the create new album function.
CVSS Score
8.3
EPSS Score
0.008
Published
2024-03-22
Cross Site Scripting (XSS) vulnerability in Lychee 3.1.6, allows remote attackers to execute arbitrary code and obtain sensitive information via the title parameter when creating an album.
CVSS Score
6.1
EPSS Score
0.002
Published
2024-03-22
Lychee is a free photo-management tool. Prior to 5.0.2, Lychee is vulnerable to an SQL injection on any binding when using mysql/mariadb. This injection is only active for users with the `.env` settings set to DB_LOG_SQL=true and DB_LOG_SQL_EXPLAIN=true. The defaults settings of Lychee are safe. The patch is provided on version 5.0.2. To work around this issue, disable SQL EXPLAIN logging.
CVSS Score
8.8
EPSS Score
0.004
Published
2023-12-28
Lychee-v3 3.2.16 is affected by a Cross Site Scripting (XSS) vulnerability in php/Access/Guest.php. The function exit will terminate the script and print the message to the user. The message will contain albumID which is controlled by the user.
CVSS Score
6.1
EPSS Score
0.003
Published
2021-12-15


Contact Us

Shodan ® - All rights reserved