CVE-2014-4614 Information

Description

Multiple cross-site request forgery (CSRF) vulnerabilities in Piwigo before 2.6.2 allow remote attackers to hijack the authentication of administrators for requests that use the (1) pwg.groups.addUser (2) pwg.groups.deleteUser (3) pwg.groups.setInfo (4) pwg.users.setInfo (5) pwg.permissions.add or (6) pwg.permissions.remove method.

Reference

http://piwigo.org/bugs/view.php?id=0003055 http://piwigo.org/releases/2.6.2 http://seclists.org/oss-sec/2014/q2/623

Share on: