LIVE · cybersecurity feed
Live wire
cve recordhigh

CVE-2017-20250

Published
CVSS7.5
Severityhigh
WeaknessCWE-22
ExploitedNot in CISA KEV

CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:N/A:N

Description

Mac Photo Gallery 3.0 contains a path traversal vulnerability that allows unauthenticated attackers to download arbitrary files by manipulating the albid parameter. Attackers can send requests to macdownload.php with directory traversal sequences to access sensitive files like wp-load.php outside the intended plugin directory.

References

← Back to the CVE Tracker

Our coverage of CVE-2017-20250

No stories yet. This page updates automatically when we publish reporting that references CVE-2017-20250.