CVE-2026-96673
HIGH
NVD
CVSS Score
7.5
Severity
HIGH
Published
Sep 23, 2026
Vendor
unknown
Description
Photoview through 2.4.0 contains an SQL injection vulnerability in the album download route that allows unauthenticated attackers to inject SQL by manipulating the album_id path segment. Attackers can supply crafted SQL expressions in the album_id parameter to extract arbitrary data from the database using time-based or blind injection techniques.
References
- https://github.com/photoview/photoview
- https://github.com/photoview/photoview/blob/v2.4.0/api/routes/downloads.go#L19-L29
- https://github.com/photoview/photoview/commit/deb1b216e047a30803dc0f48a9fc3d4c4abda594
- https://github.com/photoview/photoview/pull/1453
- https://hackmd.io/@leediay/sqli-in-download-photoview