PT-2024-33078 · Piwigo · Piwigo

Whiteshark2K

·

Published

2024-10-30

·

Updated

2024-11-01

·

CVE-2024-48311

CVSS v3.1

8.8

High

VectorAV:N/AC:L/PR:N/UI:R/S:U/C:H/I:H/A:H
Name of the Vulnerable Software and Affected Versions Piwigo version 14.5.0
Description The issue is related to a Cross-Site Request Forgery (CSRF) that can be exploited via the Edit album function. This allows an attacker to perform unintended actions on the application.
Recommendations For Piwigo version 14.5.0, consider disabling the Edit album function until a patch is available to prevent potential exploitation. Restrict access to this function to minimize the risk of CSRF attacks.

Exploit

Fix

CSRF

Weakness Enumeration

Related Identifiers

CVE-2024-48311

Affected Products

Piwigo