CVE-2024-53617: Stored XSS in LibrePhotos before version 2024w47
LibrePhotos before version 2024w47 has a stored XSS (Cross-site Scripting) allows attackers to takeover any account via uploading an HTML file on behalf of the admin user using IDOR in file upload.