⤷ Title: CVE-2025-43856: OAuth2 Account Hijacking Flaw Found in Immich, a Popular Self-Hosted Photo Platform
════════════════════════
𐀪 Author: Ddos
════════════════════════
ⴵ Time: Tue, 15 Jul 2025 00:03:14 +0000
════════════════════════
⌗ Tags: #Vulnerability Report #Account Hijacking #CSRF #CVE_2025_43856 #cybersecurity #Immich #OAuth2 #open_source #Photo Management #Video Management #Vulnerability
════════════════════════
𐀪 Author: Ddos
════════════════════════
ⴵ Time: Tue, 15 Jul 2025 00:03:14 +0000
════════════════════════
⌗ Tags: #Vulnerability Report #Account Hijacking #CSRF #CVE_2025_43856 #cybersecurity #Immich #OAuth2 #open_source #Photo Management #Video Management #Vulnerability
Daily CyberSecurity
CVE-2025-43856: OAuth2 Account Hijacking Flaw Found in Immich, a Popular Self-Hosted Photo Platform
A flaw (CVE-2025-43856) in Immich allows account hijacking via a broken OAuth2 implementation (missing state parameter check). Update to v1.132.0 immediately!