CVE-2026-42322 CRITICAL
← Quay lại danh sáchinternal/cve/categories.go), hoặc NVD chưa cung cấp đủ dữ liệu vendor/sản phẩm cho CVE này.
Mô tả
Piwigo is a full featured open source photo gallery application for the web. Prior to 16.4.0, admin/themes_standard_pages.php validates uploaded logo content by MIME type but reuses the attacker-controlled extension from std_pgs_logo when constructing the stored filename. An authenticated administrator can upload image content with a server-executable final extension, causing the file to be placed in the web-accessible logo directory and executed when requested if the web server handles that extension. This can permit arbitrary command execution, data disclosure, modification, persistence, and service disruption. This vulnerability is fixed in 16.4.0.
Chi tiết
| Trạng thái | Deferred |
| Điểm CVSS | 9.1 (v3.1) |
| Vector CVSS | CVSS:3.1/AV:N/AC:L/PR:H/UI:N/S:C/C:H/I:H/A:H |
| Ngày công bố | 23:17 25/09/2026 |
| Ngày cập nhật | 22:17 28/09/2026 |
| Nguồn dữ liệu | nvd |
CWE
Sản phẩm bị ảnh hưởng
Nguồn dữ liệu chưa cung cấp thông tin sản phẩm chi tiết.
Tài liệu tham khảo
- [security-advisories@github.com] https://github.com/Piwigo/Piwigo/commit/1e7f7262cb30e6916779f93e66d5d6579ec75a11
- [security-advisories@github.com] https://github.com/Piwigo/Piwigo/commit/4a13ec9a8f4881ae1f23bdfd24d7b90cd0802cdc
- [security-advisories@github.com] https://github.com/Piwigo/Piwigo/releases/tag/16.4.0
- [security-advisories@github.com] https://github.com/Piwigo/Piwigo/security/advisories/GHSA-7w97-5g4p-xqvv
- [134c704f-9b21-4f2e-91b3-4a467353bcc0] https://github.com/Piwigo/Piwigo/security/advisories/GHSA-7w97-5g4p-xqvv
Lịch sử thay đổi
| Thời gian | Loại | Trường | Giá trị cũ | Giá trị mới |
|---|---|---|---|---|
| 22:17 28/09/2026 | CREATED | cve | CRITICAL |