CVE-2017-10678: CSRF
Published Jun 29, 2017
·Updated
Cross-site request forgery (CSRF) vulnerability in Piwigo through 2.9.1 allows remote attackers to hijack the authentication of users for requests to delete permalinks via a crafted request.
Affected Software
1 affected component
Piwigo piwigo<=2.9.1
Remediation
Event History
Jun 29, 2017
CVE Published
via MITRE·09:00 PM
Data Sourced
via MITRE·09:00 PM
Description
Frequently Asked Questions
1
What is the severity of CVE-2017-10678?
CVE-2017-10678 has a high severity rating of 8.8.
2
What kind of vulnerability is CVE-2017-10678?
CVE-2017-10678 is a cross-site request forgery (CSRF) vulnerability.
3
How do I fix CVE-2017-10678?
To fix CVE-2017-10678, update Piwigo to a version later than 2.9.1.
4
What risks does CVE-2017-10678 pose to users?
CVE-2017-10678 allows remote attackers to hijack user authentication and perform actions such as deleting permalinks.
5
Which versions of Piwigo are affected by CVE-2017-10678?
CVE-2017-10678 affects Piwigo versions up to and including 2.9.1.