PT-2017-18937 · Piwigo · Piwigo

Eric Castaã±Eda

·

Published

2017-06-14

·

Updated

2017-06-19

·

CVE-2017-9464

CVSS v3.1

6.1

Medium

VectorAV:N/AC:L/PR:N/UI:R/S:C/C:L/I:L/A:N
Name of the Vulnerable Software and Affected Versions Piwigo versions 2.9 and prior
Description An open redirect issue allows remote attackers to redirect users to arbitrary web sites, potentially leading to phishing attacks. The redirect parameter in the identification.php component is not validated, making it vulnerable to exploitation.
Recommendations For Piwigo versions 2.9 and prior, as a temporary workaround, consider validating or restricting the use of the redirect parameter in the identification.php component to minimize the risk of exploitation. At the moment, there is no information about a newer version that contains a fix for this vulnerability.

Open Redirect

Found an issue in the description? Have something to add? Feel free to write us 👾

Weakness Enumeration

Related Identifiers

CVE-2017-9464

Affected Products

Piwigo