CVE-2017-17825
21.12.2017, 04:29
The Batch Manager component of Piwigo 2.9.2 is vulnerable to Persistent Cross Site Scripting via tags-* array parameters in an admin.php?page=batch_manager&mode=unit request. An attacker can exploit this to hijack a client's browser along with the data stored in it.
Vendor | Product | Version |
---|---|---|
piwigo | piwigo | 2.9.2 |
𝑥
= Vulnerable software versions
References