You signed in with another tab or window. Reload to refresh your session.You signed out in another tab or window. Reload to refresh your session.You switched accounts on another tab or window. Reload to refresh your session.Dismiss alert
Missing permission check when removing a photo from an album
Low
nickvergessen
published
GHSA-9chh-5prm-wp43Jun 14, 2024
Package
Photos
(Nextcloud)
Affected versions
>= 25.0.1
>= 26.0.0
Patched versions
25.0.7
26.0.2
Description
Impact
Users can remove photos from the album of registered users
Patches
It is recommended that the Nextcloud Server is upgraded to 25.0.7 or 26.0.2
It is recommended that the Nextcloud Enterprise Server is upgraded to 25.0.7 or 26.0.2
Impact
Users can remove photos from the album of registered users
Patches
It is recommended that the Nextcloud Server is upgraded to 25.0.7 or 26.0.2
It is recommended that the Nextcloud Enterprise Server is upgraded to 25.0.7 or 26.0.2
Workarounds
References
For more information
If you have any questions or comments about this advisory: