First published: Thu Dec 21 2017(Updated: )
The Configuration component of Piwigo 2.9.2 is vulnerable to Persistent Cross Site Scripting via the gallery_title parameter in an admin.php?page=configuration§ion=main request. An attacker can exploit this to hijack a client's browser along with the data stored in it.
Credit: cve@mitre.org
Affected Software | Affected Version | How to fix |
---|---|---|
Piwigo Piwigo | =2.9.2 |
Sign up to SecAlerts for real-time vulnerability data matched to your software, aggregated from hundreds of sources.
CVE-2017-17826 is a vulnerability in the Configuration component of Piwigo 2.9.2 that allows for persistent cross site scripting (XSS) attacks.
CVE-2017-17826 has a severity rating of medium with a CVSS score of 6.1.
CVE-2017-17826 can be exploited through the gallery_title parameter in an admin.php?page=configuration§ion=main request to inject malicious scripts that are executed when the targeted user visits a specific webpage.
Piwigo 2.9.2 is affected by CVE-2017-17826.
To fix CVE-2017-17826, it is recommended to update Piwigo to the latest version available, which contains the necessary security patches.