The Gallery Remote module in Menalto Gallery prior to 2.2.4 does not check permissions for unspecified GR commands, which has unknown impact and attack vectors.
menalto gallery