CVE-2017-10681: CSRF
Published Jun 29, 2017
·Updated
Cross-site request forgery (CSRF) vulnerability in Piwigo through 2.9.1 allows remote attackers to hijack the authentication of users for requests to unlock albums via a crafted request.
Affected Software
1 affected component
Piwigo piwigo<=2.9.1
Remediation
Event History
Jun 29, 2017
CVE Published
via MITRE·09:00 PM
Data Sourced
via MITRE·09:00 PM
Description
Frequently Asked Questions
1
What is the severity of CVE-2017-10681?
CVE-2017-10681 is considered a medium severity vulnerability.
2
How do I fix CVE-2017-10681?
To fix CVE-2017-10681, upgrade Piwigo to version 2.9.2 or later.
3
What type of vulnerability is CVE-2017-10681?
CVE-2017-10681 is a cross-site request forgery (CSRF) vulnerability.
4
Who is affected by CVE-2017-10681?
Users of Piwigo versions up to and including 2.9.1 are affected by CVE-2017-10681.
5
What can attackers do with CVE-2017-10681?
Attackers can use CVE-2017-10681 to hijack user authentication for requests to unlock albums.