PT-2025-47413 · Piwigo · Piwigo
CVE-2025-62406
·
Publicado
2025-11-18
·
Atualizado
2025-11-19
CVSS v3.1
8.8
Alta
| Vetor | AV:N/AC:L/PR:N/UI:R/S:U/C:H/I:H/A:H |
Name of the Vulnerable Software and Affected Versions
Piwigo versions prior to 15.7.0
Description
Piwigo is a photo gallery application for the web. The password reset function in versions prior to 15.7.0 does not validate the hostname used in the password-reset URL, which is taken directly from the HTTP request’s
Host header. This allows an attacker to send a password-reset URL with a modified hostname to a user, potentially leading to account compromise if the attacker knows or guesses the user’s username or email address.Recommendations
Update to version 15.7.0 or later.
Exploit
Correção
Encontrou algum problema na descrição? Tem algo a acrescentar? Fique à vontade para nos escrever 👾
Enumeração de Fraquezas
Identificadores relacionados
Produtos afetados
Piwigo