Piwigo 2.10.1 cross site scripting Vulnerability / Exploit
/
/
/
Exploits / Vulnerability Discovered : 2020-09-16 |
Type : webapps |
Platform : php
This exploit / vulnerability Piwigo 2.10.1 cross site scripting is for educational purposes only and if it is used you will do on your own risk!
[+] Code ...
# Exploit Title: Piwigo 2.10.1 - Cross Site Scripting
# POC by: Iridium
# Software Homepage: http://www.piwigo.org
# Version : 2.10.1
# Tested on: Linux & Windows
# Category: webapps
# Google Dork: intext: "Powered by Piwigo"
# CVE : CVE-2020-9467
######## Description ########
Piwigo 2.10.1 has stored XSS via the file parameter in a /ws.php request
because of the pwg.images.setInfo function.