Lychee-v3 3.2.16 is affected by a Cross Site Scripting (XSS) vulnerability in php/Access/Guest.php. The function exit will terminate the script and print the message to the user. The message will contain albumID which is controlled by the user.
The product does not neutralize or incorrectly neutralizes user-controllable input before it is placed in output that is used as a web page that is served to other users.
Link | Tags |
---|---|
https://github.com/LycheeOrg/Lychee | third party advisory |
https://github.com/LycheeOrg/Lychee-v3 | third party advisory |
https://github.com/LycheeOrg/LycheeOrg.github.io/blob/master/docs/releases.md#v3216 | third party advisory release notes |