CVE-2017-10680: CSRF
Published Jun 29, 2017
·Updated
Cross-site request forgery (CSRF) vulnerability in Piwigo through 2.9.1 allows remote attackers to hijack the authentication of users for requests to change a private album to public via a crafted request.
Affected Software
1 affected component
Piwigo piwigo<=2.9.1
Remediation
Event History
Jun 29, 2017
CVE Published
via MITRE·09:00 PM
Data Sourced
via MITRE·09:00 PM
Description
Frequently Asked Questions
1
What is the severity of CVE-2017-10680?
CVE-2017-10680 is classified as a medium severity vulnerability due to its potential to allow authentication hijacking.
2
How can I fix CVE-2017-10680?
To fix CVE-2017-10680, upgrade Piwigo to version 2.9.2 or later, which includes a patch for this vulnerability.
3
What vulnerabilities does CVE-2017-10680 expose in Piwigo?
CVE-2017-10680 exposes Piwigo to cross-site request forgery attacks that could allow unauthorized changes to private albums.
4
Who is affected by CVE-2017-10680?
Any user of Piwigo versions up to and including 2.9.1 is affected by CVE-2017-10680.
5
What type of vulnerability is CVE-2017-10680?
CVE-2017-10680 is a cross-site request forgery (CSRF) vulnerability.