Description
Coppermine Photo Gallery in versions 1.6.09 through 1.6.27 is vulnerable to path traversal. Unauthenticated remote attacker is able to exploit a vulnerable endpoint and construct payloads that allow to read content of any file accessible by the the web server process.This issue was fixed in version 1.6.28.
Problem types
CWE-22 Improper Limitation of a Pathname to a Restricted Directory ('Path Traversal')
Product status
1.6.09 (semver) before 1.6.28
Credits
Jan Paweł Klim
References
cert.pl/en/posts/2026/03/CVE-2026-3013
github.com/coppermine-gallery/cpg1.6.x/releases/tag/v1.6.28