CVE-2023-52082

    Dashboard / Vulnerabilities / CVE-2023-52082

    CVE-2023-52082

    Published: 28 Dec 2023Last Modified: 12 Aug 2026

    Summary: Lychee is vulnerable to an SQL Injection in explain DB queries.

    Details: Lychee is a free photo-management tool. Prior to 5.0.2, Lychee is vulnerable to an SQL injection on any binding when using mysql/mariadb. This injection is only active for users with the `.env` settings set to DB_LOG_SQL=true and DB_LOG_SQL_EXPLAIN=true. The defaults settings of Lychee are safe. The patch is provided on version 5.0.2. To work around this issue, disable SQL EXPLAIN logging.

    Affected packages

    Package

    Name:

    Purl:

    Affected ranges

    Type: GIT

    Events:

    Introduced- 94f670ac8bb5ab60b9918946e3b9b7d315a0eba3

    Affected versions

    v5.0.1
    v5.0.0
    v5.0.0-beta

    Common Vulnerability Scoring System

    Attack Vector
    Network
    Adjacent
    Local
    Physical
    Privileges Required
    None
    Low
    High
    User Interaction
    None
    Required
    Scope
    Unchanged
    Changed
    Confidentiality
    None
    Low
    High
    Integrity
    None
    Low
    High
    Availability
    None
    Low
    High
    CVE-2023-52082 | CVE-DB