Piwigo Improper Access Control Vulnerability - CVE-2016-10084 - Vulnerability Database

Piwigo Improper Access Control Vulnerability - CVE-2016-10084

High
Reference: CVE-2016-10084
Title: Piwigo Improper Access Control Vulnerability
Overview:

admin/batch_manager.php in Piwigo through 2.8.3 allows remote authenticated administrators to conduct File Inclusion attacks via the page39tab39 variable (aka the mode parameter).