Medium severity5.4NVD Advisory· Published Feb 28, 2024· Updated Jun 17, 2026
CVE-2024-26450
CVE-2024-26450
Description
An issue exists within Piwigo before v.14.2.0 allowing a malicious user to take over the application. This exploit involves chaining a Cross Site Request Forgery vulnerability to issue a Stored Cross Site Scripting payload stored within an Admin user's dashboard, executing remote JavaScript. This can be used to upload a new PHP file under an administrator and directly call that file from the victim's instance to connect back to a malicious listener.
AI Insight
LLM-synthesized narrative grounded in this CVE's description and references.
Affected products
3Patches
Vulnerability mechanics
References
1- github.com/Piwigo/Piwigo/security/advisories/GHSA-p362-cfpj-q55fnvdVendor Advisory
News mentions
0No linked articles in our index yet.