Piwigo 'ws.php' Cross-Site Request Forgery Vulnerability
BID:65811
CVE-2014-4613 |Info
Piwigo 'ws.php' Cross-Site Request Forgery Vulnerability
| Bugtraq ID: | 65811 |
| Class: | Input Validation Error |
| CVE: |
CVE-2014-4613 |
| Remote: | Yes |
| Local: | No |
| Published: | Feb 26 2014 12:00AM |
| Updated: | Jun 25 2014 02:35PM |
| Credit: | killall-9 |
| Vulnerable: | |
| Not Vulnerable: | |
Discussion
Piwigo 'ws.php' Cross-Site Request Forgery Vulnerability
Piwigo is prone to a cross-site request-forgery vulnerability.
Exploiting this issue may allow a remote attacker to perform certain administrative actions such as adding users in the context of the application.
Piwigo 2.6.1 is vulnerable; other versions may also be affected.
Piwigo is prone to a cross-site request-forgery vulnerability.
Exploiting this issue may allow a remote attacker to perform certain administrative actions such as adding users in the context of the application.
Piwigo 2.6.1 is vulnerable; other versions may also be affected.
Exploit / POC
Piwigo 'ws.php' Cross-Site Request Forgery Vulnerability
To exploit this issue, an attacker must entice an unsuspecting victim to follow a malicious URI.
Following exploit is available.
To exploit this issue, an attacker must entice an unsuspecting victim to follow a malicious URI.
Following exploit is available.
Solution / Fix
Piwigo 'ws.php' Cross-Site Request Forgery Vulnerability
Solution:
Updates are available. Please see the references or vendor advisory for more information.
Solution:
Updates are available. Please see the references or vendor advisory for more information.