Analysis and contextual insights are available on OpenCVE Cloud.
No vendor fix or workaround currently provided.
Additional remediation guidance may be available on OpenCVE Cloud.
Tracking
Sign in to view the affected projects.
| Source | ID | Title |
|---|---|---|
EUVD |
EUVD-2024-52011 | A Cross Site Scripting vulnerability in LibrePhotos before commit 32237 allows attackers to takeover any account via uploading an HTML file on behalf of the admin user using IDOR in file upload. |
Mon, 02 Dec 2024 20:15:00 +0000
| Type | Values Removed | Values Added |
|---|---|---|
| Weaknesses | CWE-639 CWE-79 |
|
| Metrics |
cvssV3_1
|
Mon, 02 Dec 2024 18:45:00 +0000
| Type | Values Removed | Values Added |
|---|---|---|
| Description | A Cross Site Scripting vulnerability in LibrePhotos before commit 32237 allows attackers to takeover any account via uploading an HTML file on behalf of the admin user using IDOR in file upload. | |
| References |
|
Subscriptions
No data.
Status: PUBLISHED
Assigner: mitre
Published:
Updated: 2024-12-02T19:23:06.899Z
Reserved: 2024-11-20T00:00:00.000Z
Link: CVE-2024-53617
Updated: 2024-12-02T19:22:43.862Z
Status : Deferred
Published: 2024-12-02T19:15:10.940
Modified: 2026-04-15T00:35:42.020
Link: CVE-2024-53617
No data.
OpenCVE Enrichment
No data.
EUVD