CVE-2018-20371: Photorange Photo Vault Project Photorange Photo Vault

Critical severity, CVSS 9.8. EPSS: 1.6% chance of exploitation in the next 30 days.

PhotoRange Photo Vault 1.2 appends the password to the URI for authorization, which makes it easier for remote attackers to bypass intended GET restrictions via a brute-force approach, as demonstrated by "GET /login.html__passwd1" and "GET /login.html__passwd2" and so on.

Affected products

Published 2018-12-23. Last modified 2026-06-17.