vendor:
PhotoShow
by:
LSCP Responsible Disclosure Lab
7.5
CVSS
HIGH
Remote Code Execution
CWE
Product Name: PhotoShow
Affected Version From: 3
Affected Version To: 3
Patch Exists: NO
Related CWE:
CPE: a:thibaud-rohmer:photoshow:3.0
Platforms Tested: Ubuntu 20.04 LTS
2023
PhotoShow 3.0 – Remote Code Execution
The PhotoShow version 3.0 is vulnerable to remote code execution. By exploiting this vulnerability, an attacker can execute arbitrary code on the target system.
Mitigation:
Apply the latest security patches provided by the vendor. Additionally, restrict access to the application from untrusted networks.