Benoît Viguier
8 exploits
Active since Dec 2023
Lychee has Broken Access Control in SharingController::listAll() leaks private album sharing metadata to unauthorized users
CVSS 4.3
Lychee has SSRF bypass via incomplete IP validation in Photo::fromUrl — loopback and link-local IPs not blocked
CVSS 5.0
Lychee has SSRF bypass via DNS rebinding — PhotoUrlRule only validates IP addresses, not hostnames resolving to internal IPs
CVSS 4.3
Lychee Vulnerable to Stored XSS via Photo Description in RSS/Atom/JSON Feed (No Sanitization on Public Endpoint)
CVSS 5.4
Lychee 4.9.3-5.0.2 - SQL Injection via SQL EXPLAIN Logging
CVSS 8.8
Lychee 6.6.6-6.6.9 - Path Traversal in SecurePathController
CVSS 7.5
Lychee < 6.6.13 - Server-Side Request Forgery via Photo::fromUrl Endpoint
CVSS 3.0
Lychee < 7.1.0 - Incorrect Authorization via Album Password Unlock
CVSS 4.3