Access Control Issues in Haptiq's Online Photo Proofing Gallery
CVE-2025-24590
5.3MEDIUM
Key Information:
- Vendor
- WordPress
- Vendor
- CVE Published:
- 27 January 2025
Summary
The Online Photo Proofing Gallery by Haptiq suffers from a missing authorization vulnerability, which allows an attacker to exploit incorrectly configured access control security levels. This could enable unauthorized access to sensitive features or data within the application, impacting the gallery's security integrity. Users of affected versions up to 2.4.0 should take immediate action to mitigate this risk.
Affected Version(s)
picu – Online Photo Proofing Gallery <= 2.4.0
References
CVSS V3.1
Score:
5.3
Severity:
MEDIUM
Confidentiality:
Low
Integrity:
None
Availability:
Low
Attack Vector:
Network
Attack Complexity:
Low
Privileges Required:
None
User Interaction:
None
Scope:
Unchanged
Timeline
Vulnerability published
Vulnerability Reserved
Credit
thiennv (Patchstack Alliance)