Description
Cross-site scripting (XSS) vulnerability in zp-core/admin.php in Zenphoto 1.2.5 allows remote attackers to inject arbitrary web script or HTML via the from parameter.
Remediation
References
Related Vulnerabilities
WordPress Plugin Absolute Privacy 'abpr_authenticateUser()' Security Bypass (2.0.5)
Microsoft SQL Server CVE-2023-23384 Vulnerability (CVE-2023-23384)
MediaWiki Insertion of Sensitive Information into Log File Vulnerability (CVE-2024-40598)
MediaWiki Allocation of Resources Without Limits or Throttling Vulnerability (CVE-2022-34750)