Server-Side Request Forgery Vulnerability in Event Gallery Extension by Svenbluege
CVE-2026-102777
6.3MEDIUM
What is CVE-2026-102777?
The Event Gallery extension by Svenbluege is compromised by a server-side request forgery vulnerability stemming from the Google Photos picker feature. In versions earlier than 6.6.0, a lack of validation allows an adversary to exploit the backend upload page. The vulnerability permits the unauthorized fetching of content and the potential leakage of OAuth access tokens belonging to Google Photos accounts, effectively compromising user accounts if manipulated by a malicious actor. This exploitation can occur without proper verification of the request source, allowing an attacker to access sensitive data within the server's network, thereby posing significant risks to installed systems.
Affected Version(s)
Event Gallery for Joomla 1.0.0-6.6.0
