GHSA-2mp4-gjj5-8xj5HighCVSS 7.5

Photoview through 2.4.0 contains an SQL injection vulnerability in the album download route that...

Published
September 23, 2026
Last Modified
September 23, 2026

🔗 CVE IDs covered (1)

📋 Description

Photoview through 2.4.0 contains an SQL injection vulnerability in the album download route that allows unauthenticated attackers to inject SQL by manipulating the album_id path segment. Attackers can supply crafted SQL expressions in the album_id parameter to extract arbitrary data from the database using time-based or blind injection techniques.

🔗 References (8)