CVE-2021-31783: High severity piwigo vulnerability
Published Apr 26, 2021
·Updated
showdefault.php in the LocalFilesEditor extension before 11.4.0.1 for Piwigo allows Local File Inclusion because the file parameter is not validated with a proper regular-expression check.
Affected Software
1 affected component
Piwigo Localfiles Editor Piwigo<11.4.0.1
Remediation
Event History
Apr 26, 2021
CVE Published
via MITRE·06:05 PM
Data Sourced
via MITRE·06:05 PM
Description
Frequently Asked Questions
1
What is CVE-2021-31783?
CVE-2021-31783 is a vulnerability in the LocalFilesEditor extension for Piwigo that allows local file inclusion.
2
How does CVE-2021-31783 affect Piwigo?
CVE-2021-31783 affects Piwigo versions before 11.4.0.1 that have the LocalFilesEditor extension installed.
3
What is the severity of CVE-2021-31783?
CVE-2021-31783 has a severity rating of 7.5 (high).
4
How can I fix CVE-2021-31783?
To fix CVE-2021-31783, upgrade to Piwigo version 11.4.0.1 or higher and ensure the LocalFilesEditor extension is updated to the latest version.
5
Where can I find more information about CVE-2021-31783?
You can find more information about CVE-2021-31783 on the Piwigo website and the GitHub repository for the LocalFilesEditor extension.