Sploitus

CVE-2017-10679

No indexed exploits for CVE-2017-10679 yet

Piwigo through 2.9.1 allows remote attackers to obtain sensitive information about the descriptive name of a permalink by examining the redirect URL that is returned in a request for the permalink ID number of a private album. The permalink ID numbers are easily guessed.

Affected products
Piwigo
Piwigo
≤ 2.9.1
Fix
Available
CVSS 3.0
7.5 HIGH
EPSS
2.2% (81th percentile)
Weakness
CWE-200
NVD status
Modified
Published
2017-06-29
CVE-2017-10679 at NVD
Authoritative description, scoring and affected products

No indexed exploits for CVE-2017-10679 yet

Our index is partial: it proves presence, never absence

No exploit for CVE-2017-10679 has been indexed yet. Our index is built from live traffic and upstream syncs, so this page can only say what it knows — not that no exploit exists.