Persistent Cross Site Scripting Vulnerability in Piwigo 2.9.2 Configuration Component
CVE-2017-17826 · MEDIUM Severity
AV:N/AC:M/AU:N/C:N/I:P/A:N
The Configuration component of Piwigo 2.9.2 is vulnerable to Persistent Cross Site Scripting via the gallery_title parameter in an admin.php?page=configuration§ion=main request. An attacker can exploit this to hijack a client's browser along with the data stored in it.
Learn more about our Web Application Penetration Testing UK.