show_default.php in the LocalFilesEditor extension before 11.4.0.1 for Piwigo allows Local File Inclusion because the file parameter is not validated with a proper regular-expression check.
The product does not sufficiently verify the origin or authenticity of data, in a way that causes it to accept invalid data.
Link | Tags |
---|---|
https://piwigo.org/ext/index.php?cid=null | third party advisory release notes |
https://github.com/Piwigo/LocalFilesEditor/issues/2 | third party advisory issue tracking |
https://github.com/Piwigo/LocalFilesEditor/commit/dda691d3e45bfd166ac175c70bd8b91cb4917b6b | third party advisory patch |