CVE-2024-26450: XSS
An issue exists within Piwigo before v.14.2.0 allowing a malicious user to take over the application. This exploit involves chaining a Cross Site Request Forgery vulnerability to issue a Stored Cross Site Scripting payload stored within an Admin user's dashboard, executing remote JavaScript. This can be used to upload a new PHP file under an administrator and directly call that file from the victim's instance to connect back to a malicious listener.
Affected Software
Event History
Frequently Asked Questions
What is the severity of CVE-2024-26450?
CVE-2024-26450 is considered a critical vulnerability as it allows a malicious user to take over the Piwigo application.
How does CVE-2024-26450 work?
CVE-2024-26450 exploits a combination of Cross Site Request Forgery and Stored Cross Site Scripting vulnerabilities to execute remote JavaScript.
Which versions of Piwigo are affected by CVE-2024-26450?
CVE-2024-26450 affects all versions of Piwigo before v.14.2.0.
How do I fix CVE-2024-26450?
To fix CVE-2024-26450, you need to update your Piwigo installation to version 14.2.0 or later.
What are the potential impacts of CVE-2024-26450?
The potential impacts of CVE-2024-26450 include unauthorized access, data theft, and the ability to execute arbitrary code on the server.