Goal Reached Thanks to every supporter — we hit 100%!

Goal: 1000 CNY · Raised: 1336 CNY

100%

CVE-2025-62406— Piwigo is vulnerable to one-click account takeover by modifying the password-reset link

CVSS 8.1 · High EPSS 0.39% · P32

Possible ATT&CK Techniques 1AI

T1566.002 · Spearphishing Link
Get alerts for future matching vulnerabilitiesLog in to subscribe

I. Basic Information for CVE-2025-62406

Vulnerability Information

Have questions about the vulnerability? See if Shenlong's analysis helps!
View Shenlong Deep Dive ↗

Although we use advanced large model technology, its output may still contain inaccurate or outdated information.Shenlong tries to ensure data accuracy, but please verify and judge based on the actual situation.

Vulnerability Title
Piwigo is vulnerable to one-click account takeover by modifying the password-reset link
Source: CVE Program / CVE List V5
Vulnerability Description
Piwigo is a full featured open source photo gallery application for the web. In Piwigo 15.6.0, using the password reset function allows sending a password-reset URL by entering an existing username or email address. However, the hostname used to construct this URL is taken from the HTTP request's Host header and is not validated at all. Therefore, an attacker can send a password-reset URL with a modified hostname to an existing user whose username or email the attacker knows or guesses. This issue has been patched in version 15.7.0.
Source: CVE Program / CVE List V5
CVSS Information
CVSS:3.1/AV:N/AC:L/PR:N/UI:R/S:U/C:H/I:H/A:N
Source: CVE Program / CVE List V5
Vulnerability Type
忘记口令恢复机制弱
Source: CVE Program / CVE List V5
Vulnerability Title
Piwigo 授权问题漏洞
Source: CNNVD (China National Vulnerability Database)
Vulnerability Description
Piwigo是Piwigo开源的一套基于Web的开源图片库软件。该软件包括图片管理、图片分类和权限管理等功能。 Piwigo 15.6.0版本存在授权问题漏洞,该漏洞源于密码重置功能未验证Host标头,可能导致账户接管。
Source: CNNVD (China National Vulnerability Database)
CVSS Information
N/A
Source: CNNVD (China National Vulnerability Database)
Vulnerability Type
N/A
Source: CNNVD (China National Vulnerability Database)

Affected Products

VendorProductAffected VersionsCPESubscribe
PiwigoPiwigo = 15.6.0 -

II. Public POCs for CVE-2025-62406

#POC DescriptionSource LinkShenlong Link
AI-Generated POCPremium
Qwen3.6-35B-A3B · 7813 chars
Pro+ exclusive includes:
Vulnerability reproduction recording (real sandbox build + trigger, exclusive)
In-depth vulnerability mechanism
Trigger conditions & impact
Full executable POC code
Exploit chain & mitigation
POC zip download
100+ AI POC generations per month

III. Intelligence Information for CVE-2025-62406

登录查看更多情报信息。

Patches & Fixes for CVE-2025-62406 (1)

IV. Related Vulnerabilities

V. Comments for CVE-2025-62406

No comments yet


Leave a comment