Junglewise Threat Intelligence

CVE-2017-5608: Piwigo XSS in image upload filename

CVE-2017-5608 · Severity: medium · CVSS 6.1 · Published 2017-01-28

Technologies: Piwigo. Vendors: Piwigo.

Executive brief

Piwigo, an open-source photo gallery software, is vulnerable to a security flaw in its image upload system. An attacker can upload a file with a specially crafted name containing malicious code. If an administrator or another user views the uploaded image, that code could execute in their browser, potentially leading to unauthorized actions or data theft.

Technical details

A stored cross-site scripting (XSS) vulnerability exists in Piwigo's image upload functionality (specifically via the pwg.images.upload method in ws.php). The application fails to properly sanitize the filename of uploaded images before displaying them in the web interface. An attacker can exploit this by uploading an image with a filename containing HTML or JavaScript payloads. When a user or administrator views the image or its associated metadata, the payload executes in the context of their session. This can lead to session hijacking or unauthorized administrative actions. The issue is fixed in version 2.8.6 by implementing better input handling for uploaded filenames.

Affected products

  • Piwigo Piwigo < 2.8.6

Timeline

  • 2017-01-04: disclosed: Issue reported on GitHub
  • 2017-01-27: patched: Version 2.8.6 released
  • 2017-01-28: advisory: NVD publication date

References

Related threats