Description
Cross-site scripting (XSS) vulnerability in admin.php in Piwigo 2.9.0 and earlier allows remote attackers to inject arbitrary web script or HTML via the page parameter.
Remediation
References
Related Vulnerabilities
WordPress Plugin Nmedia MailChimp Widget 'abs_path' Parameter Remote File Include (3.1)
Drupal Core 8.x Multiple Vulnerabilities (8.0.0 - 8.3.3)
WordPress Plugin Contact Form by Supsystic Cross-Site Scripting (1.7.19)
Apache HTTP Server CVE-2009-1191 Vulnerability (CVE-2009-1191)
Moodle Permissions, Privileges, and Access Controls Vulnerability (CVE-2011-4589)