MEDIUM
Multiple cross-site request forgery (CSRF) vulnerabilities in TinyWebGallery (TWG) before 1.8.8 allow remote attackers to hijack the authentication of administrators for requests that (1) add a user via an adduser action to admin/index.php or (2) conduct static PHP code injection attacks in .htusers.php via the user parameter to admin/index.php
Published Apr 24, 2015
6.8
MEDIUMCVSS 2.0
EPSS 0.69%
Description
Affected products
Remediation
Metrics
References (3)
Change history (0)
No recorded changes yet.