Impact
A path traversal flaw exists in the i.php component of the Image Derivative Handler in Piwigo up to version 16.3.0. By manipulating the file request, an attacker can cause the server to resolve directories outside the intended image locations, potentially reading sensitive files on the filesystem or executing arbitrary code if additional vulnerabilities exist. The CVE notes that remote exploitation is possible and that public proof‑of‑concepts have been disclosed.
Affected Systems
This vulnerability affects the Piwigo content‑management system, specifically the Image Derivative Handler implemented in i.php. All installations running Piwigo version 16.3.0 or earlier are susceptible; newer releases contain the fix. The weakness exists in the file handling logic for derivative image creation.
Risk and Exploitability
The vulnerability carries a CVSS score of 6.9, indicating a moderate to high risk rating. The EPSS score is not available, so the current probability of exploitation in the wild cannot be quantified. It is not listed in the CISA KEV catalog, but publicly available proofs of concept exist, so attackers may continue to exploit it. The attack vector is remote and does not require authentication, making it broadly accessible to anyone who can reach the web application.
OpenCVE Enrichment