CVE-2023-22903
Severity CVSS v4.0:
Pending analysis
Type:
Unavailable / Other
Publication date:
10/01/2023
Last modified:
07/04/2025
Description
api/views/user.py in LibrePhotos before e19e539 has incorrect access control.
Impact
Base Score 3.x
9.80
Severity 3.x
CRITICAL
Vulnerable products and versions
| CPE | From | Up to |
|---|---|---|
| cpe:2.3:a:librephotos_project:librephotos:*:*:*:*:*:*:*:* | 2023-01-09 (excluding) |
To consult the complete list of CPE names with products and versions, see this page
References to Advisories, Solutions, and Tools
- https://github.com/LibrePhotos/librephotos/commit/e19e539356df77f6f59e7d1eea22d452b268e120
- https://raw.githubusercontent.com/go-compile/security-advisories/master/CVE-2023-22903.pdf
- https://github.com/LibrePhotos/librephotos/commit/e19e539356df77f6f59e7d1eea22d452b268e120
- https://raw.githubusercontent.com/go-compile/security-advisories/master/CVE-2023-22903.pdf



