CVE-2013-1468

Piwigo < 2.4.7 - Cross-Site Request Forgery via LocalFiles Editor Plugin

Title source: llm
STIX 2.1

Exploitation Summary

EIP tracks 1 public exploit for CVE-2013-1468. PoCs published by High-Tech Bridge SA.

AI-analyzed exploit summary The exploit demonstrates a CSRF vulnerability (CVE-2013-1468) allowing arbitrary PHP file creation and a path traversal vulnerability (CVE-2013-1469) enabling arbitrary file read/deletion in Piwigo 2.4.6. The PoC includes HTML/JS for CSRF and a direct URL for path traversal.

Description

Cross-site request forgery (CSRF) vulnerability in the LocalFiles Editor plugin in Piwigo before 2.4.7 allows remote attackers to hijack the authentication of administrators for requests that create arbitrary PHP files via unspecified vectors.

Exploits (1)

exploitdb WORKING POC VERIFIED
by High-Tech Bridge SA · textwebappsphp
https://www.exploit-db.com/exploits/24561

The exploit demonstrates a CSRF vulnerability (CVE-2013-1468) allowing arbitrary PHP file creation and a path traversal vulnerability (CVE-2013-1469) enabling arbitrary file read/deletion in Piwigo 2.4.6. The PoC includes HTML/JS for CSRF and a direct URL for path traversal.

Classification
Working Poc 90%
Attack Type
Other
Complexity
Trivial
Reliability
Reliable
Target: Piwigo 2.4.6
Auth required
Prerequisites: Admin session for CSRF · LocalFiles Editor plugin enabled for CSRF · Default install.php presence for path traversal
devstral-2 · analyzed Feb 16, 2026 Full analysis →

References (9)

Core 9
Core References
Various Sources x_refsource_confirm
http://piwigo.org/forum/viewtopic.php?id=21470
Release Notes x_refsource_confirm
http://piwigo.org/releases/2.4.7
Vendor Advisory third-party-advisory x_refsource_secunia
http://secunia.com/advisories/52228
Exploit exploit x_refsource_exploit-db
http://www.exploit-db.com/exploits/24561
Various Sources x_refsource_confirm
http://piwigo.org/bugs/view.php?id=0002844
Third Party Advisory, VDB Entry vdb-entry x_refsource_osvdb
http://www.osvdb.org/90504
Third Party Advisory mailing-list x_refsource_bugtraq
http://archives.neohapsis.com/archives/bugtraq/2013-02/0153.html

Scores

EPSS 0.0573
EPSS Percentile 92.0%

Details

CWE
CWE-352
Status published
Products (50)
piwigo/piwigo 1.0.0
piwigo/piwigo 1.0.1
piwigo/piwigo 1.0.2
piwigo/piwigo 1.1.0
piwigo/piwigo 1.2.0
piwigo/piwigo 1.2.1
piwigo/piwigo 1.3.0
piwigo/piwigo 1.3.1
piwigo/piwigo 1.3.2
piwigo/piwigo 1.3.3
... and 40 more
Published Mar 14, 2013
Tracked Since Feb 18, 2026