SQL Injection Vulnerability in Photoview by Photoview
CVE-2026-96673
8.7HIGH
What is CVE-2026-96673?
In Photoview version 2.4.0, a vulnerability exists that allows unauthenticated users to exploit an SQL injection flaw in the album download route. By manipulating the album_id path segment, attackers can inject arbitrary SQL commands through crafted album_id parameters. This could lead to the unauthorized exposure of sensitive database information via time-based or blind SQL injection techniques.
Affected Version(s)
Photoview 0 <= 2.4.0
Photoview deb1b216e047a30803dc0f48a9fc3d4c4abda594
