First published: Fri Mar 16 2018(Updated: )
Cross-site request forgery (CSRF) vulnerability in the administration panel in Piwigo before 2.6.2 allows remote attackers to hijack the authentication of administrators for requests that add users via a pwg.users.add action in a request to ws.php.
Credit: cve@mitre.org
Affected Software | Affected Version | How to fix |
---|---|---|
Piwigo Piwigo | <2.6.2 |
Sign up to SecAlerts for real-time vulnerability data matched to your software, aggregated from hundreds of sources.
The vulnerability ID for this CSRF vulnerability is CVE-2014-4613.
The severity of CVE-2014-4613 is medium with a CVSS score of 6.5.
The CSRF vulnerability allows attackers to hijack administrator authentication by exploiting a weakness in the administration panel that allows remote attackers to add users via a pwg.users.add action in a request to ws.php.
The CSRF vulnerability affects Piwigo versions up to and excluding 2.6.2.
To fix the CSRF vulnerability, you should update Piwigo to version 2.6.2 or a later version.