Nextcloud Photos is a photo management app. Users can remove photos from the album of registered users. It is recommended that the Nextcloud Server is upgraded to 25.0.7 or 26.0.2 and the Nextcloud Enterprise Server is upgraded to 25.0.7 or 26.0.2.
The product does not restrict or incorrectly restricts access to a resource from an unauthorized actor.
The product does not perform an authorization check when an actor attempts to access a resource or perform an action.
Link | Tags |
---|---|
https://github.com/nextcloud/security-advisories/security/advisories/GHSA-9chh-5prm-wp43 | vendor advisory |
https://github.com/nextcloud/photos/pull/1749 | patch |
https://hackerone.com/reports/1946298 | issue tracking |