Description
The management panel in Piwigo 2.9.3 has stored XSS via the name parameter in a /admin.php?page=photo-${photo_number} request. CSRF exploitation, related to CVE-2017-10681, may be possible.
Remediation
References
Related Vulnerabilities
SharePoint CVE-2019-1205 Vulnerability (CVE-2019-1205)
WordPress Plugin Events Manager Cross-Site Scripting (5.8.1.3)
WordPress Plugin eShop Multiple Vulnerabilities (6.3.13)
WordPress Plugin Feed Them Social-for Twitter feed, Youtube and more Cross-Site Scripting (1.6.9)
WordPress Plugin Download from files Arbitrary File Upload (1.48)