Benoît Viguier
8 exploits
Active since Dec 2023
Lychee has Broken Access Control in SharingController::listAll() leaks private album sharing metadata to unauthorized users
CVSS 4.3
Lychee has SSRF bypass via incomplete IP validation in Photo::fromUrl — loopback and link-local IPs not blocked
CVSS 5.0
Lychee has SSRF bypass via DNS rebinding — PhotoUrlRule only validates IP addresses, not hostnames resolving to internal IPs
CVSS 4.3
Lychee Vulnerable to Stored XSS via Photo Description in RSS/Atom/JSON Feed (No Sanitization on Public Endpoint)
CVSS 5.4
Lychee <5.0.2 - SQL Injection
CVSS 8.8
Lychee <6.6.10 - Path Traversal
CVSS 7.5
Lychee <6.6.13 - SSRF
CVSS 3.0
Lychee < 7.1.0 - Incorrect Authorization
CVSS 4.3