CVE-2016-10513: XSS
Published Oct 10, 2017
·Updated
Cross Site Scripting (XSS) exists in Piwigo before 2.8.3 via a crafted search expression to include/functionssearch.inc.php.
Affected Software
1 affected component
Piwigo piwigo<=2.8.2
Remediation
Event History
Oct 10, 2017
CVE Published
via MITRE·08:00 PM
Data Sourced
via MITRE·08:00 PM
Description
Frequently Asked Questions
1
What is the severity of CVE-2016-10513?
CVE-2016-10513 is classified as a medium severity vulnerability due to its potential for cross-site scripting (XSS) attacks.
2
How do I fix CVE-2016-10513?
To fix CVE-2016-10513, upgrade Piwigo to version 2.8.3 or later.
3
Which versions of Piwigo are affected by CVE-2016-10513?
Piwigo versions prior to 2.8.3, including 2.8.2 and earlier, are affected by CVE-2016-10513.
4
What type of vulnerability is CVE-2016-10513?
CVE-2016-10513 is a cross-site scripting (XSS) vulnerability that allows attackers to inject malicious scripts.
5
How can I identify if CVE-2016-10513 is present in my Piwigo installation?
You can identify CVE-2016-10513 in your Piwigo installation if you are using a version before 2.8.3 and if users can input search expressions without proper validation.