Gentoo Websites Logo
Go to: Gentoo Home Documentation Forums Lists Bugs Planet Store Wiki Get Gentoo!
Bug 649792 (CVE-2018-1722, CVE-2018-1723, CVE-2018-1724) - <www-apps/piwigo-2.9.4: multiple vulnerabilities
Summary: <www-apps/piwigo-2.9.4: multiple vulnerabilities
Status: RESOLVED FIXED
Alias: CVE-2018-1722, CVE-2018-1723, CVE-2018-1724
Product: Gentoo Security
Classification: Unclassified
Component: Vulnerabilities (show other bugs)
Hardware: All Linux
: Normal trivial (vote)
Assignee: Gentoo Security
URL: https://github.com/summ3rf/Vulner/blo...
Whiteboard: ~4 [noglsa cve]
Keywords:
Depends on:
Blocks:
 
Reported: 2018-03-06 20:23 UTC by Dimitris Nakos (sokan)
Modified: 2018-09-05 13:05 UTC (History)
1 user (show)

See Also:
Package list:
Runtime testing required: ---


Attachments

Note You need to log in before you can comment on or make changes to this bug.
Description Dimitris Nakos (sokan) 2018-03-06 20:23:46 UTC
CVE-2018-7722:
The management panel in Piwigo 2.9.3 has stored XSS via the name parameter in a /ws.php?format=json request. CSRF exploitation, related to CVE-2017-10681, may be possible. 

CVE-2018-7223:
The management panel in Piwigo 2.9.3 has stored XSS via the virtual_name parameter in a /admin.php?page=cat_list request, a different issue than CVE-2017-9836. CSRF exploitation, related to CVE-2017-10681, may be possible. 

CVE-2018-7224:
The management panel in Piwigo 2.9.3 has stored XSS via the name parameter in a /admin.php?page=photo-${photo_number} request. CSRF exploitation, related to CVE-2017-10681, may be possible. 

- Gentoo Security Padawan -
Comment 1 Bernard Cafarelli gentoo-dev 2018-07-16 15:42:24 UTC
Upstream released 2.9.4, which is in tree now, and I dropped 2.9.3 (only older version)

https://piwigo.org/release-2.9.4