CVE detail
CVE-2024-26450 — CVE-2024-26450
Published 2024-02-28 · Modified 2026-06-17 · Vendor piwigo · Product piwigo · Source nvd
MEDIUM
severity
CVSS-derived band
0.0019
EPSS probability
exploitation probability, 30d
8.0%
EPSS percentile
percentile vs all CVEs
NOT LISTED
CISA KEV
known exploited catalog
Description
An issue exists within Piwigo before v.14.2.0 allowing a malicious user to take over the application. This exploit involves chaining a Cross Site Request Forgery vulnerability to issue a Stored Cross Site Scripting payload stored within an Admin user's dashboard, executing remote JavaScript. This can be used to upload a new PHP file under an administrator and directly call that file from the victim's instance to connect back to a malicious listener.
Remediation
No vendor-published fix data in our corpus for this CVE. Check the references below or the vendor's PSIRT / security advisories page.
References