The Google Photos picker of the upload page fetches the thumbnails of the picked images through the server, with the access token of the Google Photos account. The task took the address to fetch from the request without checking it and asked for no form token. A prepared page on another web site could therefore make the server send the access token of the account to any address, or fetch addresses inside the network of the server, in the name of a logged in administrator; a back-end user with the permission Manage could do the same directly. The token is valid for about an hour and reaches what the picker session of the account reaches.
- Needed: a Google Photos account set up in Event Gallery. Then either no account - the victim is logged in to the back end with the permission Manage of Event Gallery and opens a prepared page - or a back-end login with Manage.
- Affected: 5.4.0 to 6.5.0; the picker came with 5.4.0.
- Fixed in: 6.6.0. The server fetches only https addresses of Google’s image hosts, and the four requests of the picker need the form token and the permission Manage.
-
Severity: CVSS 4.0 5.1 (
CVSS:4.0/AV:N/AC:L/AT:N/PR:N/UI:A/VC:L/VI:N/VA:N/SC:L/SI:N/SA:N), CWE-918 and CWE-522. - CVE: CVE-2026-102777.
All prices include VAT. The gross price will vary depending on the selected shipping country.