CVE-2015-2034: XSS
Cross-site scripting (XSS) vulnerability in the administrative backend in Piwigo before 2.7.4 allows remote attackers to inject arbitrary web script or HTML via the page parameter to admin.php.
Affected Software
Remediation
Patch Available
Event History
Frequently Asked Questions
What is the severity of CVE-2015-2034?
CVE-2015-2034 is classified as a medium severity vulnerability due to its potential for exploitation through cross-site scripting.
How do I fix CVE-2015-2034?
To fix CVE-2015-2034, update Piwigo to version 2.7.4 or later to ensure the vulnerability is patched.
What impact does CVE-2015-2034 have on my Piwigo installation?
CVE-2015-2034 allows remote attackers to inject arbitrary web scripts or HTML into the administrative backend, potentially compromising the website's integrity.
Who is affected by CVE-2015-2034?
CVE-2015-2034 affects Piwigo installations prior to version 2.7.4, specifically versions up to 2.7.3.
What type of attack does CVE-2015-2034 enable?
CVE-2015-2034 enables cross-site scripting (XSS) attacks, allowing attackers to execute malicious scripts in the context of the admin interface.