CVE-2017-9836: XSS
Published Jun 24, 2017
·Updated
Cross-site scripting (XSS) vulnerability in Piwigo 2.9.1 allows remote authenticated administrators to inject arbitrary web script or HTML via the virtualname parameter to /admin.php (i.e., creating a virtual album).
Affected Software
1 affected component
Piwigo piwigo=2.9.1
Remediation
Patch Available
Event History
Jun 24, 2017
CVE Published
via MITRE·03:00 PM
Data Sourced
via MITRE·03:00 PM
Description
Frequently Asked Questions
1
What is the severity of CVE-2017-9836?
CVE-2017-9836 is classified as a medium severity cross-site scripting (XSS) vulnerability.
2
How do I fix CVE-2017-9836?
To mitigate CVE-2017-9836, upgrade Piwigo to the latest version that addresses this vulnerability.
3
Who is affected by CVE-2017-9836?
CVE-2017-9836 affects remote authenticated administrators using Piwigo version 2.9.1.
4
What type of vulnerability is CVE-2017-9836?
CVE-2017-9836 is a cross-site scripting (XSS) vulnerability that allows script injection.
5
What specific component is vulnerable in CVE-2017-9836?
The vulnerable component in CVE-2017-9836 is the virtual_name parameter in the /admin.php file.