CVE-2024-48311: CSRF
Published Oct 31, 2024
·Updated
Piwigo v14.5.0 was discovered to contain a Cross-Site Request Forgery (CSRF) via the Edit album function.
Affected Software
2 affected components
Piwigo piwigo
Piwigo piwigo=14.5.0
Event History
Oct 31, 2024
CVE Published
via MITRE·12:00 AM
Data Sourced
via MITRE·12:00 AM
Description
Data Sourced
via NVD·02:15 AM
DescriptionSeverityWeakness
Frequently Asked Questions
1
What is the severity of CVE-2024-48311?
CVE-2024-48311 is classified as a medium severity vulnerability due to its potential to exploit user sessions.
2
How do I fix CVE-2024-48311?
To fix CVE-2024-48311, update Piwigo to the latest version that addresses the CSRF issue.
3
What types of attacks are possible due to CVE-2024-48311?
CVE-2024-48311 allows attackers to perform unauthorized actions on behalf of users via CSRF attacks.
4
Is CVE-2024-48311 present in earlier versions of Piwigo?
Yes, CVE-2024-48311 affects Piwigo versions prior to 14.5.0.
5
What specific function in Piwigo is vulnerable due to CVE-2024-48311?
The vulnerable function in CVE-2024-48311 is the Edit album function.