First published: Tue Mar 06 2018(Updated: )
The management panel in Piwigo 2.9.3 has stored XSS via the name parameter in a /admin.php?page=photo-${photo_number} request. CSRF exploitation, related to CVE-2017-10681, may be possible.
Credit: cve@mitre.org
Affected Software | Affected Version | How to fix |
---|---|---|
Piwigo Piwigo | =2.9.3 |
Sign up to SecAlerts for real-time vulnerability data matched to your software, aggregated from hundreds of sources.
The vulnerability ID of this security issue is CVE-2018-7724.
The severity of CVE-2018-7724 is medium, with a severity score of 5.4.
The affected software version for CVE-2018-7724 is Piwigo 2.9.3.
This vulnerability can be exploited by injecting malicious scripts into the name parameter in a /admin.php?page=photo-${photo_number} request, leading to stored Cross-Site Scripting (XSS) attacks.
CSRF exploitation may be possible in relation to CVE-2018-7724, which is related to CVE-2017-10681.