CVE-2018-7724: XSS
Published Mar 6, 2018
·Updated
The management panel in Piwigo 2.9.3 has stored XSS via the name parameter in a /admin.php?page=photo-${photonumber} request. CSRF exploitation, related to CVE-2017-10681, may be possible.
Affected Software
1 affected component
Piwigo piwigo=2.9.3
Event History
Mar 6, 2018
CVE Published
via MITRE·05:00 PM
Data Sourced
via MITRE·05:00 PM
Description
Data Sourced
via NVD·05:29 PM
DescriptionSeverityWeaknessAffected Software
Frequently Asked Questions
1
What is the vulnerability ID of this security issue?
The vulnerability ID of this security issue is CVE-2018-7724.
2
What is the severity of CVE-2018-7724?
The severity of CVE-2018-7724 is medium, with a severity score of 5.4.
3
What is the affected software version for CVE-2018-7724?
The affected software version for CVE-2018-7724 is Piwigo 2.9.3.
4
How can this vulnerability be exploited?
This vulnerability can be exploited by injecting malicious scripts into the name parameter in a /admin.php?page=photo-${photo_number} request, leading to stored Cross-Site Scripting (XSS) attacks.
5
Is CSRF exploitation possible in relation to CVE-2018-7724?
CSRF exploitation may be possible in relation to CVE-2018-7724, which is related to CVE-2017-10681.