Cross-site request forgery in Piwigo - #VU127937
Published: February 12, 2024 / Updated: April 25, 2026
Piwigo
Piwigo.org
Description
The vulnerability allows a remote user to execute arbitrary code.
The vulnerability exists due to a cross-site request forgery vulnerability and stored cross-site scripting in the administrator dashboard when handling crafted requests that store malicious script content. A remote user can submit a crafted request to inject a stored script payload and upload a PHP file to execute arbitrary code.
Exploitation requires chaining the cross-site request forgery issue with the stored cross-site scripting issue, and the malicious script executes in an administrator user's dashboard.