Description
novaGallery is a php image gallery. Prior to version 2.1.1, a path traversal vulnerability has been identified in novaGallery. This allows unauthenticated users to read image files outside the intended gallery root directory. This issue has been patched in version 2.1.1.
Problem types
CWE-22: Improper Limitation of a Pathname to a Restricted Directory ('Path Traversal')
Product status
References
github.com/...allery/security/advisories/GHSA-wv5j-98c7-frm9
github.com/...allery/security/advisories/GHSA-wv5j-98c7-frm9
github.com/...ommit/46fe7b0f79f429e18c8cff3f92360c4513732ba6
github.com/novafacile/novagallery/releases/tag/v2.1.1