PT-2025-47413 · Piwigo · Piwigo

CVE-2025-62406

·

Publicado

2025-11-18

·

Atualizado

2025-11-19

CVSS v3.1

8.8

Alta

VetorAV:N/AC:L/PR:N/UI:R/S:U/C:H/I:H/A:H
Name of the Vulnerable Software and Affected Versions Piwigo versions prior to 15.7.0
Description Piwigo is a photo gallery application for the web. The password reset function in versions prior to 15.7.0 does not validate the hostname used in the password-reset URL, which is taken directly from the HTTP request’s Host header. This allows an attacker to send a password-reset URL with a modified hostname to a user, potentially leading to account compromise if the attacker knows or guesses the user’s username or email address.
Recommendations Update to version 15.7.0 or later.

Exploit

Correção

Encontrou algum problema na descrição? Tem algo a acrescentar? Fique à vontade para nos escrever 👾

Enumeração de Fraquezas

Identificadores relacionados

CVE-2025-62406
GHSA-9986-W7JF-33F6

Produtos afetados

Piwigo