PatchSiren cyber security CVE debrief
CVE-2017-5608 Piwigo CVE debrief
CVE-2017-5608 is a cross-site scripting (XSS) issue in Piwigo’s image upload flow. According to the CVE record, versions before 2.8.6 could allow a remote attacker to inject arbitrary web script or HTML through a crafted image filename. The vulnerability is publicly documented in NVD and tied to a vendor fix in Piwigo 2.8.6.
- Vendor
- Piwigo
- Product
- Unknown
- CVSS
- MEDIUM 6.1
- CISA KEV
- Not listed in stored evidence
- Original CVE published
- 2017-01-28
- Original CVE updated
- 2026-05-13
- Advisory published
- 2017-01-28
- Advisory updated
- 2026-05-13
Who should care
Piwigo administrators, site owners, and application security teams should care most if their deployments accept user-uploaded images or display uploaded filenames in the web interface. Any environment running Piwigo 2.8.5 or earlier is in scope for review.
Technical summary
NVD lists the weakness as CWE-79 (improper neutralization of input during web page generation) and rates the issue with CVSS 3.0 vector AV:N/AC:L/PR:N/UI:R/S:C/C:L/I:L/A:N. The affected condition is specifically the image upload function, where a crafted filename can be reflected or rendered in a way that enables script or HTML injection. The supplied reference set includes the 2.8.6 release notes, a GitHub issue, and a fixing commit, indicating the issue was addressed in that release.
Defensive priority
Medium. The issue is remotely reachable but requires user interaction, and the expected impact is limited to confidentiality and integrity rather than availability. It is still important because XSS can enable account abuse, session theft, or unauthorized actions in the affected web application context.
Recommended defensive actions
- Upgrade Piwigo to version 2.8.6 or later as indicated by the vendor release notes.
- Verify that uploaded filenames are safely encoded before being displayed anywhere in the UI, including galleries, admin views, and confirmation pages.
- Review any custom themes, plugins, or templates that render upload metadata or filenames and ensure they do not bypass output encoding.
- Check whether users can upload images in your deployment and limit upload permissions where possible.
- After upgrading, validate that filenames containing special characters are normalized or escaped in all user-facing views.
Evidence notes
The CVE record and NVD detail identify the issue as XSS in the image upload function of Piwigo before 2.8.6. NVD associates the vulnerability with CWE-79 and the CVSS 3.0 vector AV:N/AC:L/PR:N/UI:R/S:C/C:L/I:L/A:N. The supplied references point to the vendor release notes for 2.8.6, a GitHub issue, and a GitHub commit, which together support the remediation timing and affected-version boundary.
Sources and references
Verified primary and authoritative sources
-
CVE-2017-5608 CVE Program record
Publisher, destination, and source semantics verified
URL: https://www.cve.org/CVERecord?id=CVE-2017-5608
CVE Program - Official CVE Program record with source-provided CVE metadata.
-
CVE-2017-5608 NVD vulnerability detail
Publisher, destination, and source semantics verified
URL: https://nvd.nist.gov/vuln/detail/CVE-2017-5608
NIST National Vulnerability Database - Official NIST NVD detail page and source-specific vulnerability assessment.
Supplemental references
-
Mitigation or vendor reference
Unverified legacy reference
URL: https://github.com/Piwigo/Piwigo/commit/6ec3f2d0fae0437f0c2cc8c475a26fb6aeb0d4cb
[email protected] - Issue Tracking, Patch, Third Party Advisory
-
Mitigation or vendor reference
Unverified legacy reference
URL: https://github.com/Piwigo/Piwigo/issues/600
[email protected] - Issue Tracking, Patch, Third Party Advisory
Methodology and review provenance
AI-assisted synthesis based on stored public vulnerability evidence. System validation, approval state, and publication status do not by themselves establish human review of this revision. PatchSiren helps prioritize defensive review and does not prove exposure or remediation on any system.