CVE-2023-33995Missing Authorization in Photo Gallery

Severity
4.3MEDIUMNVD
EPSS
0.1%
top 68.08%
CISA KEV
Not in KEV
Exploit
No known exploits
Timeline
PublishedDec 13

Description

Missing Authorization vulnerability in Photo Gallery Team Photo Gallery by 10Web allows Exploiting Incorrectly Configured Access Control Security Levels.This issue affects Photo Gallery by 10Web: from n/a through 1.8.15.

CVSS vector

CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:U/C:L/I:N/A:NExploitability: 2.8 | Impact: 1.4

Affected Packages2 packages

NVD10web/photo_gallery< 1.8.16

🔴Vulnerability Details

2
CVEList
WordPress Photo Gallery by 10Web plugin <= 1.8.15 - Broken Access Control vulnerability2024-12-13
GHSA
GHSA-67wr-qmv5-xmr6: Missing Authorization vulnerability in Photo Gallery Team Photo Gallery by 10Web allows Exploiting Incorrectly Configured Access Control Security Leve2024-12-13
CVE-2023-33995 — Missing Authorization in Photo Gallery | cvebase