Description
Piwigo through 2.9.1 allows remote attackers to obtain sensitive information about the descriptive name of a permalink by examining the redirect URL that is returned in a request for the permalink ID number of a private album. The permalink ID numbers are easily guessed.
Remediation
References
Related Vulnerabilities
MediaWiki CVE-2023-36674 Vulnerability (CVE-2023-36674)
WordPress Plugin WP eCommerce HTML Injection (3.8.7.1)
WordPress Plugin Asgaros Forum Multiple Vulnerabilities (1.15.14)
Joomla! Core 3.x.x Multiple Vulnerabilities (3.0.0 - 3.10.6)
WordPress Plugin WP-Lister Lite for Amazon Cross-Site Scripting (2.4.3)