CVE-2023-27040
Published Mar 16, 2023Simple Image Gallery v1.0 was discovered to contain a remote code execution (RCE) vulnerability via the username parameter.
Vendor archive
3 CVEs tagged to vendor simple_image_gallery_web_app_project — 2 Critical, 1 High, 0 Medium, 0 Low, 0 Unrated.
Simple Image Gallery v1.0 was discovered to contain a remote code execution (RCE) vulnerability via the username parameter.
A SQL injection vulnerability exits on the Simple Image Gallery System 1.0 application through "id" parameter on the album page.
An unrestricted file upload on Simple Image Gallery Web App can be exploited to upload a web shell and executed to gain unauthorized access to the server hosting the web app.