CVE-2017-10680
29.06.2017, 21:29
Cross-site request forgery (CSRF) vulnerability in Piwigo through 2.9.1 allows remote attackers to hijack the authentication of users for requests to change a private album to public via a crafted request.
Vendor | Product | Version |
---|---|---|
piwigo | piwigo | 𝑥 ≤ 2.9.1 |
𝑥
= Vulnerable software versions
Common Weakness Enumeration
References