CyberRota Analysis
AI-GeneratedThe authorization bypass vulnerability in Photoview versions prior to 2.4.0 allows authenticated users to exploit the shareAlbum GraphQL mutation, enabling them to generate share links for albums owned by other users by supplying arbitrary album IDs. This can lead to unauthorized exposure of photos and sub-albums, allowing attackers to access sensitive content while maintaining control over the share token settings. Organizations using this software should prioritize patching to mitigate the risk of data exposure and unauthorized access.
Public Exploit Signal
A public exploit, PoC, GitHub repository or Metasploit reference was detected for this CVE.
Note: these links are listed for security research and verification purposes only.
Original NVD Description
Photoview through 2.4.0 contains an authorization bypass vulnerability in the shareAlbum GraphQL mutation that allows authenticated users to create share links for albums owned by other users. Attackers can supply arbitrary album IDs to generate working share tokens for victim albums, exposing photos and sub-albums to anyone with the link while retaining indefinite control over token settings.