CVE-2017-17775: XSS
Published Dec 20, 2017
·Updated
Piwigo 2.9.2 has XSS via the name parameter in an admin.php?page=album-3-properties request.
Affected Software
1 affected component
Piwigo piwigo=2.9.2
Event History
Dec 20, 2017
CVE Published
via MITRE·03:00 AM
Data Sourced
via MITRE·03:00 AM
Description
Frequently Asked Questions
1
What is CVE-2017-17775?
CVE-2017-17775 is a vulnerability in Piwigo 2.9.2 that allows for cross-site scripting (XSS) attacks.
2
What is the severity of CVE-2017-17775?
The severity of CVE-2017-17775 is medium with a CVSS score of 6.1.
3
How does CVE-2017-17775 affect Piwigo?
CVE-2017-17775 affects Piwigo 2.9.2, specifically the admin.php?page=album-3-properties request, allowing for XSS attacks via the name parameter.
4
How can I fix CVE-2017-17775?
To fix CVE-2017-17775, update Piwigo to a version higher than 2.9.2.
5
What is CWE-79?
CWE-79 is a weakness in software that can lead to cross-site scripting (XSS) attacks.