CVE-2024-53276
CVSS 3.1 Score 6.1 of 10 (medium)
Details
Summary
CVE-2024-53276 is a vulnerability affecting Home-Gallery.org, a self-hosted open-source web gallery. In versions 1.15.0 and earlier, an open CORS policy in app.js exposes the gallery to potential attacks. An attacker can make cross-site requests to home-gallery, enabling them to view images and access any endpoint on the gallery. This vulnerability could potentially allow an attacker to view preview images and gain unauthorized access to any static files or endpoints that may contain sensitive information, if introduced in the future. Home-gallery is generally safe from cross-site requests due to most pages requiring JavaScript, but the vulnerability can bypass this protection. It is recommended that users update to the latest version of Home-Gallery to mitigate this risk.
Prevent cyber attacks with Recorded Future by prioritizing and patching critical vulnerabilities being exploited by threat actors targeting your industry. Book your demo to learn more.
Affected Products
- Home > Gallery