CVE-2018-20371: Photorange Photo Vault Project Photorange Photo Vault
Critical severity, CVSS 9.8. EPSS: 1.6% chance of exploitation in the next 30 days.
PhotoRange Photo Vault 1.2 appends the password to the URI for authorization, which makes it easier for remote attackers to bypass intended GET restrictions via a brute-force approach, as demonstrated by "GET /login.html__passwd1" and "GET /login.html__passwd2" and so on.
Affected products
- Photorange Photo Vault Project Photorange Photo Vault: version 1.2 only
Published 2018-12-23. Last modified 2026-06-17.