Looking for the vulnerability index of Invicti's legacy products?
Piwigo Cross-Site Request Forgery (CSRF) Vulnerability (CVE-2018-7724) - Vulnerability Database

Piwigo Cross-Site Request Forgery (CSRF) Vulnerability (CVE-2018-7724)

Description

The management panel in Piwigo 2.9.3 has stored XSS via the name parameter in a /admin.php?page=photo-${photo_number} request. CSRF exploitation, related to CVE-2017-10681, may be possible.

References

Related Vulnerabilities