CVE-2021-43675

Severity CVSS v4.0:
Pending analysis
Type:
CWE-79 Cross-Site Scripting (XSS)
Publication date:
15/12/2021
Last modified:
21/01/2024

Description

Lychee-v3 3.2.16 is affected by a Cross Site Scripting (XSS) vulnerability in php/Access/Guest.php. The function exit will terminate the script and print the message to the user. The message will contain albumID which is controlled by the user.

Vulnerable products and versions

CPE From Up to
cpe:2.3:a:lycheeorg:lychee:3.2.16:*:*:*:*:*:*:*