Metrics
Affected Vendors & Products
No advisories yet.
Solution
No solution given by the vendor.
Workaround
No workaround given by the vendor.
Wed, 11 Feb 2026 22:15:00 +0000
| Type | Values Removed | Values Added |
|---|---|---|
| First Time appeared |
Minigal
Minigal minigal |
|
| Vendors & Products |
Minigal
Minigal minigal |
Wed, 11 Feb 2026 17:15:00 +0000
| Type | Values Removed | Values Added |
|---|---|---|
| Metrics |
ssvc
|
Wed, 11 Feb 2026 16:15:00 +0000
| Type | Values Removed | Values Added |
|---|---|---|
| Description | MiniGal Nano versions 0.3.5 and prior contain a path traversal vulnerability in index.php via the dir parameter. The application appends user-controlled input to the photos directory and attempts to prevent traversal by removing dot-dot sequences, but this protection can be bypassed using crafted directory patterns. An attacker can exploit this behavior to cause the application to enumerate and display image files from unintended filesystem locations that are readable by the web server, resulting in unintended information disclosure. | |
| Title | MiniGal Nano <= 0.3.5 Path Traversal via dir Parameter | |
| Weaknesses | CWE-22 | |
| References |
| |
| Metrics |
cvssV4_0
|
Projects
Sign in to view the affected projects.
Status: PUBLISHED
Assigner: VulnCheck
Published:
Updated: 2026-02-11T16:14:21.590Z
Reserved: 2026-02-06T19:12:03.464Z
Link: CVE-2026-25869
Updated: 2026-02-11T16:13:18.962Z
Status : Awaiting Analysis
Published: 2026-02-11T16:16:06.813
Modified: 2026-02-11T18:06:04.010
Link: CVE-2026-25869
No data.
OpenCVE Enrichment
Updated: 2026-02-11T21:37:49Z