CVE-2016-10084

Severity CVSS v4.0:
Pending analysis
Type:
CWE-284 Improper Access Control
Publication date:
30/12/2016
Last modified:
12/04/2025

Description

admin/batch_manager.php in Piwigo through 2.8.3 allows remote authenticated administrators to conduct File Inclusion attacks via the $page['tab'] variable (aka the mode parameter).

Vulnerable products and versions

CPE From Up to
cpe:2.3:a:piwigo:piwigo:*:*:*:*:*:*:*:* 2.8.3 (including)