Description
Cross-site scripting (XSS) vulnerability in include/functions_metadata.inc.php in Piwigo before 2.4.6 allows remote attackers to inject arbitrary web script or HTML via the Make field in IPTC Exif metadata within an image uploaded to the Community plugin.
Remediation
References
Related Vulnerabilities
Atlassian Jira CVE-2021-26075 Vulnerability (CVE-2021-26075)
Plone CMS Exposure of Sensitive Information to an Unauthorized Actor Vulnerability (CVE-2012-5505)
phpMyAdmin Improper Authentication Vulnerability (CVE-2022-23807)
Atlassian Jira Authorization Bypass Through User-Controlled Key Vulnerability (CVE-2021-41306)