Description
Multiple cross-site scripting (XSS) vulnerabilities in register.php in Piwigo 2.0.9 and earlier allow remote attackers to inject arbitrary web script or HTML via the (1) login and (2) mail_address parameters.
Remediation
References
Related Vulnerabilities
WordPress Plugin Social Login Lite For WooCommerce Security Bypass (1.6.0)
Apache HTTP Server Server-Side Request Forgery (SSRF) Vulnerability (CVE-2021-40438)
Apache Tomcat Permissions, Privileges, and Access Controls Vulnerability (CVE-2013-0346)
XWiki Allocation of Resources Without Limits or Throttling Vulnerability (CVE-2022-41932)