Vulnerabilities
Vulnerable Software

Vulnerability Details CVE-2024-26450

An issue exists within Piwigo before v.14.2.0 allowing a malicious user to take over the application. This exploit involves chaining a Cross Site Request Forgery vulnerability to issue a Stored Cross Site Scripting payload stored within an Admin user's dashboard, executing remote JavaScript. This can be used to upload a new PHP file under an administrator and directly call that file from the victim's instance to connect back to a malicious listener.
Exploit prediction scoring system (EPSS) score
EPSS Score 0.003
EPSS Ranking 55.8%
CVSS Severity
CVSS v3 Score 5.4
Products affected by CVE-2024-26450
  • Piwigo » Piwigo » Version: 14.3.0
    cpe:2.3:a:piwigo:piwigo:14.3.0
  • Piwigo » Piwigo » Version: 14.4.0
    cpe:2.3:a:piwigo:piwigo:14.4.0
  • Piwigo » Piwigo » Version: 14.5.0
    cpe:2.3:a:piwigo:piwigo:14.5.0
  • Piwigo » Piwigo » Version: 15.0.0
    cpe:2.3:a:piwigo:piwigo:15.0.0
  • Piwigo » Piwigo » Version: 15.1.0
    cpe:2.3:a:piwigo:piwigo:15.1.0
  • Piwigo » Piwigo » Version: 15.2.0
    cpe:2.3:a:piwigo:piwigo:15.2.0
  • Piwigo » Piwigo » Version: 15.3.0
    cpe:2.3:a:piwigo:piwigo:15.3.0
  • Piwigo » Piwigo » Version: 15.4.0
    cpe:2.3:a:piwigo:piwigo:15.4.0
  • Piwigo » Piwigo » Version: 15.5.0
    cpe:2.3:a:piwigo:piwigo:15.5.0


Contact Us

Shodan ® - All rights reserved