Vulnerabilities > PHP Kobo > Photo Gallery CMS Free > 1.0.1

DATE CVE VULNERABILITY TITLE RISK
2015-08-22 CVE-2015-2983 Cross-Site Request Forgery (CSRF) vulnerability in PHP Kobo Photo Gallery CMS Free 1.0.0/1.0.1
Cross-site request forgery (CSRF) vulnerability in admin.php in PHP Kobo Photo Gallery CMS for PC, smartphone and feature phone 1.0.1 Free and earlier allows remote attackers to hijack the authentication of arbitrary users.
network
php-kobo CWE-352
6.8
2015-08-22 CVE-2015-2982 Cross-site Scripting vulnerability in PHP Kobo Photo Gallery CMS Free 1.0.0/1.0.1
Cross-site scripting (XSS) vulnerability in jquery.lightbox-0.5.min.js in PHP Kobo Photo Gallery CMS for PC, smartphone and feature phone 1.0.1 Free and earlier allows remote authenticated users to inject arbitrary web script or HTML via unspecified input to admin.php.
network
php-kobo CWE-79
4.3