vendor:
Piwigo CMS
by:
sajith
5.5
CVSS
MEDIUM
Stored XSS, CSRF
79, 352
CWE
Product Name: Piwigo CMS
Affected Version From: Piwigo 2.5.3
Affected Version To: Piwigo 2.5.3
Patch Exists: NO
Related CWE:
CPE:
Platforms Tested:
Piwigo 2.5.3 CMS:Multiple vulnerability’s
The Piwigo CMS version 2.5.3 is vulnerable to Stored XSS on multiple parameters and CSRF vulnerability. In the first vulnerability, an attacker can inject malicious payload in the album name and execute arbitrary code. The payload can also be executed when managing albums. In the second vulnerability, an attacker can exploit the 'add a user' functionality using CSRF vulnerability.
Mitigation:
Apply the latest patch or upgrade to a newer version of the CMS. Avoid using untrusted inputs in the album name or other parameters.