High severity8.8NVD Advisory· Published Dec 21, 2017· Updated May 13, 2026
CVE-2017-17827
CVE-2017-17827
Description
Piwigo 2.9.2 is vulnerable to Cross-Site Request Forgery via /admin.php?page=configuration§ion=main or /admin.php?page=batch_manager&mode=unit. An attacker can exploit this to coerce an admin user into performing unintended actions.
Affected products
1Patches
0No patches discovered yet.
Vulnerability mechanics
AI mechanics synthesis has not run for this CVE yet.
References
3- github.com/Piwigo/Piwigo/commit/c3b4c6f7f0ddeaea492080fb8211d7b4cfedaf6fnvdThird Party Advisory
- github.com/Piwigo/Piwigo/issues/822nvdThird Party Advisory
- github.com/sahildhar/sahildhar.github.io/blob/master/research/reports/Piwigo_2.9.2/Cross%20Site%20Request%20Forgery%20in%20Piwigo%202.9.2.mdnvdThird Party Advisory
News mentions
0No linked articles in our index yet.