Description
Piwigo 2.9.2 is vulnerable to Cross-Site Request Forgery via /admin.php?page=configuration§ion=main or /admin.php?page=batch_manager&mode=unit. An attacker can exploit this to coerce an admin user into performing unintended actions.
Remediation
References
Related Vulnerabilities
WordPress Plugin Persian Woocommerce SMS Cross-Site Scripting (3.3.2)
WordPress Plugin EZP Coming Soon Page Cross-Site Scripting (1.0.0)
MySQL CVE-2017-3467 Vulnerability (CVE-2017-3467)
Microsoft SQL Server Improper Input Validation Vulnerability (CVE-2001-0509)
PHP Resource Management Errors Vulnerability (CVE-2010-4697)