#VU31344 Cross-site request forgery in Piwigo - CVE-2014-4613
Published: March 16, 2018 / Updated: July 20, 2020
Piwigo
Piwigo.org
Description
The vulnerability allows a remote attacker to perform cross-site request forgery attacks.
The vulnerability exists due to insufficient validation of the HTTP request origin. A remote attacker can trick the victim to visit a specially crafted web page and perform arbitrary actions on behalf of the victim on the vulnerable website.
Remediation
External links
- http://osvdb.org/show/osvdb/103774
- http://packetstormsecurity.com/files/125438/Piwigo-2.6.1-Cross-Site-Request-Forgery.html
- http://piwigo.org/bugs/view.php?id=0003055
- http://piwigo.org/releases/2.6.2
- http://seclists.org/oss-sec/2014/q2/610
- http://seclists.org/oss-sec/2014/q2/623
- http://www.exploit-db.com/exploits/31916
- http://www.securityfocus.com/bid/65811