Skip to content

CSRF + XSS to RCE

Critical
plegall published GHSA-8g2g-6f2c-6h7j Mar 1, 2024

Package

piwigo

Affected versions

> 14.2.0

Patched versions

None

Description

An issue exists where a user is able to have an admin user execute remote JavaScript giving access to an attacker to upload remote code facilitating code execution on the underlying server infrastructure.

Severity

Critical

CVE ID

No known CVE

Weaknesses

No CWEs

Credits