Description
Piwigo version 12.2.0 is vulnerable to stored cross-site scripting (XSS), which can lead to privilege escalation. In this way, admin can steal webmaster's cookies to get the webmaster's access.
Remediation
References
Related Vulnerabilities
WordPress Plugin Integration for Contact Form 7 and Infusionsoft Cross-Site Scripting (1.1.2)
WordPress Plugin Restricted Site Access Unspecified Vulnerability (2.0)
WordPress Plugin HUSKY-Products Filter Professional for WooCommerce Multiple Vulnerabilities (1.1.9)
Oracle JRE CVE-2012-1541 Vulnerability (CVE-2012-1541)
MediaWiki Incorrect Permission Assignment for Critical Resource Vulnerability (CVE-2022-47927)