CYBERHAWK / CVE / CVE-2017-20250
CVE-2017-20250
HIGH
CVSS 7.5
other
The flaw
Mac Photo Gallery 3.0 contains a path traversal vulnerability that allows unauthenticated attackers to download arbitrary files by manipulating the albid parameter. Attackers can send requests to macdownload.php with directory traversal seq
What to do
Review advisory and patch per vendor guidance.