CVE-2018-7723: XSS
The management panel in Piwigo 2.9.3 has stored XSS via the virtualname parameter in a /admin.php?page=catlist request, a different issue than CVE-2017-9836. CSRF exploitation, related to CVE-2017-10681, may be possible.
Affected Software
Event History
Frequently Asked Questions
What is CVE-2018-7723?
CVE-2018-7723 is a vulnerability in the management panel of Piwigo 2.9.3 that allows for stored Cross-Site Scripting (XSS) attacks.
How severe is CVE-2018-7723?
CVE-2018-7723 has a severity score of 5.4, which is considered medium severity.
How does CVE-2018-7723 affect Piwigo?
CVE-2018-7723 affects Piwigo 2.9.3, allowing for stored XSS attacks via the virtual_name parameter in a /admin.php?page=cat_list request.
Is there a fix for CVE-2018-7723?
At the time of this writing, there is no official fix available for CVE-2018-7723. It is recommended to follow the mitigation steps provided by the vendor or consider upgrading to a patched version when it becomes available.
Are there any known exploits or proof-of-concept for CVE-2018-7723?
Yes, there is a known exploit available for CVE-2018-7723. The vulnerability details and exploit code can be found at the provided reference link.