CVE-2013-1468

Piwigo < 2.4.6 - CSRF

Title source: rule
STIX 2.1

Description

Cross-site request forgery (CSRF) vulnerability in the LocalFiles Editor plugin in Piwigo before 2.4.7 allows remote attackers to hijack the authentication of administrators for requests that create arbitrary PHP files via unspecified vectors.

Exploits (1)

exploitdb WORKING POC VERIFIED
by High-Tech Bridge SA · textwebappsphp
https://www.exploit-db.com/exploits/24561

References (9)

Core 9
Core References
Various Sources x_refsource_confirm
http://piwigo.org/forum/viewtopic.php?id=21470
Release Notes x_refsource_confirm
http://piwigo.org/releases/2.4.7
Vendor Advisory third-party-advisory x_refsource_secunia
http://secunia.com/advisories/52228
Exploit exploit x_refsource_exploit-db
http://www.exploit-db.com/exploits/24561
Various Sources x_refsource_confirm
http://piwigo.org/bugs/view.php?id=0002844
Third Party Advisory, VDB Entry vdb-entry x_refsource_osvdb
http://www.osvdb.org/90504
Third Party Advisory mailing-list x_refsource_bugtraq
http://archives.neohapsis.com/archives/bugtraq/2013-02/0153.html

Scores

EPSS 0.1885
EPSS Percentile 95.3%

Details

CWE
CWE-352
Status published
Products (50)
piwigo/piwigo 1.0.0
piwigo/piwigo 1.0.1
piwigo/piwigo 1.0.2
piwigo/piwigo 1.1.0
piwigo/piwigo 1.2.0
piwigo/piwigo 1.2.1
piwigo/piwigo 1.3.0
piwigo/piwigo 1.3.1
piwigo/piwigo 1.3.2
piwigo/piwigo 1.3.3
... and 40 more
Published Mar 14, 2013
Tracked Since Feb 18, 2026