CVE-2014-4614

NameCVE-2014-4614
DescriptionMultiple cross-site request forgery (CSRF) vulnerabilities in Piwigo before 2.6.2 allow remote attackers to hijack the authentication of administrators for requests that use the (1) pwg.groups.addUser, (2) pwg.groups.deleteUser, (3) pwg.groups.setInfo, (4) pwg.users.setInfo, (5) pwg.permissions.add, or (6) pwg.permissions.remove method.
SourceCVE (at NVD; CERT, ENISA, LWN, oss-sec, fulldisc, Debian ELTS, Red Hat, Ubuntu, Gentoo, SUSE bugzilla/CVE, GitHub advisories/code/issues, web search, more)

The information below is based on the following data on fixed versions.

PackageTypeReleaseFixed VersionUrgencyOriginDebian Bugs
piwigosourcesqueeze(unfixed)end-of-life
piwigosource(unstable)(unfixed)low

Notes

[squeeze] - piwigo <end-of-life> (Minor issue)
Request to mark the package as unsupported in #779104

Search for package or bug name: Reporting problems