CVE-2017-10679
29.06.2017, 21:29
Piwigo through 2.9.1 allows remote attackers to obtain sensitive information about the descriptive name of a permalink by examining the redirect URL that is returned in a request for the permalink ID number of a private album. The permalink ID numbers are easily guessed.Enginsight
Vendor | Product | Version |
---|---|---|
piwigo | piwigo | 𝑥 ≤ 2.9.1 |
𝑥
= Vulnerable software versions
Common Weakness Enumeration