PHP code injection in TinyWebGallery before 1.8.8 allows remote authenticated users with admin privileges to inject arbitrary code into the .htusers.php file.
2020-01-09T21:15:11.123
2024-11-21T01:39:57.990
Modified
CVSSv3.1: 7.2 (HIGH)
AV:N/AC:L/Au:S/C:P/I:P/A:P
8.0
6.4
| Type | Vendor | Product | Version/Range | Vulnerable? | 
|---|---|---|---|---|
| Application | tinywebgallery | tinywebgallery | < 1.8.8 | Yes |