Description
An authenticated cross-site scripting (XSS) vulnerability in Piwigo v14.5.0 allows attackers to execute arbitrary web scripts or HTML via a crafted payload injected into the Album Name parameter under the Add Album function.
Remediation
References
Related Vulnerabilities
Oracle Database Server CVE-2009-1972 Vulnerability (CVE-2009-1972)
Python Inefficient Regular Expression Complexity Vulnerability (CVE-2024-6232)
MySQL CVE-2014-6551 Vulnerability (CVE-2014-6551)
WordPress Plugin Social Sharing Toolkit Cross-Site Scripting (2.6)
WordPress Plugin Pierre's Wordspew 'wordspew.php' Multiple SQL Injection Vulnerabilities (5.61)