CVE-2018-7722: XSS
Published Mar 6, 2018
·Updated
The management panel in Piwigo 2.9.3 has stored XSS via the name parameter in a /ws.php?format=json request. CSRF exploitation, related to CVE-2017-10681, may be possible.
Affected Software
1 affected component
Piwigo piwigo=2.9.3
Event History
Mar 6, 2018
CVE Published
via MITRE·05:00 PM
Data Sourced
via MITRE·05:00 PM
Description
Data Sourced
via NVD·05:29 PM
DescriptionSeverityWeaknessAffected Software
Frequently Asked Questions
1
What is the severity of CVE-2018-7722?
The severity of CVE-2018-7722 is medium with a CVSS score of 5.4.
2
How does CVE-2018-7722 affect Piwigo?
CVE-2018-7722 affects Piwigo version 2.9.3.
3
What is the vulnerability type of CVE-2018-7722?
CVE-2018-7722 is a stored cross-site scripting (XSS) vulnerability.
4
Can CSRF exploitation be possible with CVE-2018-7722?
CSRF exploitation may be possible with CVE-2018-7722, which is related to the vulnerability CVE-2017-10681.
5
How do I fix CVE-2018-7722?
To fix CVE-2018-7722, upgrade Piwigo to a version that is not affected by the vulnerability.