CVE-2017-17827: CSRF
Piwigo 2.9.2 is vulnerable to Cross-Site Request Forgery via /admin.php?page=configuration§ion=main or /admin.php?page=batchmanager&mode=unit. An attacker can exploit this to coerce an admin user into performing unintended actions.
Affected Software
Event History
Frequently Asked Questions
What is the vulnerability ID of this Piwigo vulnerability?
The vulnerability ID is CVE-2017-17827.
What is the severity of CVE-2017-17827?
The severity of CVE-2017-17827 is high.
What is the affected software version of CVE-2017-17827?
The affected software version of CVE-2017-17827 is Piwigo 2.9.2.
How can an attacker exploit CVE-2017-17827?
An attacker can exploit CVE-2017-17827 to coerce an admin user into performing unintended actions.
Are there any references available for CVE-2017-17827?
Yes, there are references available for CVE-2017-17827. You can find them at the following links: [link1](https://github.com/Piwigo/Piwigo/commit/c3b4c6f7f0ddeaea492080fb8211d7b4cfedaf6f), [link2](https://github.com/Piwigo/Piwigo/issues/822), [link3](https://github.com/sahildhar/sahildhar.github.io/blob/master/research/reports/Piwigo_2.9.2/Cross%20Site%20Request%20Forgery%20in%20Piwigo%202.9.2.md).