Description
Cross-site request forgery (CSRF) vulnerability in the LocalFiles Editor plugin in Piwigo before 2.4.7 allows remote attackers to hijack the authentication of administrators for requests that create arbitrary PHP files via unspecified vectors.
Exploits (1)
exploitdb
WORKING POC
VERIFIED
by High-Tech Bridge SA · textwebappsphp
https://www.exploit-db.com/exploits/24561
References (9)
Core 9
Core References
Various Sources x_refsource_confirm
http://piwigo.org/forum/viewtopic.php?id=21470
Release Notes x_refsource_confirm
http://piwigo.org/releases/2.4.7
Exploit x_refsource_misc
https://www.htbridge.com/advisory/HTB23144
Vendor Advisory third-party-advisory
x_refsource_secunia
http://secunia.com/advisories/52228
Exploit x_refsource_misc
http://packetstormsecurity.com/files/120592/Piwigo-2.4.6-Cross-Site-Request-Forgery-Traversal.html
Exploit exploit
x_refsource_exploit-db
http://www.exploit-db.com/exploits/24561
Various Sources x_refsource_confirm
http://piwigo.org/bugs/view.php?id=0002844
Third Party Advisory, VDB Entry vdb-entry
x_refsource_osvdb
http://www.osvdb.org/90504
Third Party Advisory mailing-list
x_refsource_bugtraq
http://archives.neohapsis.com/archives/bugtraq/2013-02/0153.html
Scores
EPSS
0.1885
EPSS Percentile
95.3%
Details
CWE
CWE-352
Status
published
Products (50)
piwigo/piwigo
1.0.0
piwigo/piwigo
1.0.1
piwigo/piwigo
1.0.2
piwigo/piwigo
1.1.0
piwigo/piwigo
1.2.0
piwigo/piwigo
1.2.1
piwigo/piwigo
1.3.0
piwigo/piwigo
1.3.1
piwigo/piwigo
1.3.2
piwigo/piwigo
1.3.3
... and 40 more
Published
Mar 14, 2013
Tracked Since
Feb 18, 2026