Piwigo Cross-Site Request Forgery (CSRF) Vulnerability - CVE-2017-17827
Reference:
CVE-2017-17827
Title:
Piwigo Cross-Site Request Forgery (CSRF) Vulnerability
Overview:
Piwigo 2.9.2 is vulnerable to Cross-Site Request Forgery via /admin.phppageconfigurationampsectionmain or /admin.phppagebatch_managerampmodeunit. An attacker can exploit this to coerce an admin user into performing unintended actions.