CVE-2021-43675

Lychee-v3 3.2.16 is affected by a Cross Site Scripting (XSS) vulnerability in php/Access/Guest.php. The function exit will terminate the script and print the message to the user. The message will contain albumID which is controlled by the user.
References
Advertisement

NeevaHost hosting service

Configurations

Configuration 1 (hide)

cpe:2.3:a:lycheeorganisation:lychee:3.2.16:*:*:*:*:*:*:*

Information

Published : 2021-12-15 08:15

Updated : 2021-12-17 12:23


NVD link : CVE-2021-43675

Mitre link : CVE-2021-43675


JSON object : View

CWE
CWE-79

Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting')

Advertisement

dedicated server usa

Products Affected

lycheeorganisation

  • lychee