Access Control Issues in Haptiq's Online Photo Proofing Gallery
CVE-2025-24590

5.3MEDIUM

Key Information:

Vendor
WordPress
Vendor
CVE Published:
27 January 2025

Summary

The Online Photo Proofing Gallery by Haptiq suffers from a missing authorization vulnerability, which allows an attacker to exploit incorrectly configured access control security levels. This could enable unauthorized access to sensitive features or data within the application, impacting the gallery's security integrity. Users of affected versions up to 2.4.0 should take immediate action to mitigate this risk.

Affected Version(s)

picu – Online Photo Proofing Gallery <= 2.4.0

References

CVSS V3.1

Score:
5.3
Severity:
MEDIUM
Confidentiality:
Low
Integrity:
None
Availability:
Low
Attack Vector:
Network
Attack Complexity:
Low
Privileges Required:
None
User Interaction:
None
Scope:
Unchanged

Timeline

  • Vulnerability published

  • Vulnerability Reserved

Credit

thiennv (Patchstack Alliance)
.