PT-2025-7723 · Unknown · Photo Gallery

Mika

·

Published

2025-02-24

·

Updated

2025-03-01

·

CVE-2025-27276

CVSS v3.1

8.8

High

VectorAV:N/AC:L/PR:N/UI:R/S:U/C:H/I:H/A:H
Name of the Vulnerable Software and Affected Versions Photo Gallery ( Responsive ) versions prior to 4.0
Description A Cross-Site Request Forgery (CSRF) issue allows Privilege Escalation. This issue enables an attacker to perform actions on behalf of another user without their knowledge or consent.
Recommendations For versions prior to 4.0, update to version 4.0 or later to resolve the issue.

Fix

LPE

CSRF

Weakness Enumeration

Related Identifiers

CVE-2025-27276

Affected Products

Photo Gallery