Description
Incomplete blacklist in sanitize_string in Zenphoto before 1.4.9 allows remote attackers to conduct cross-site scripting (XSS) attacks.
Remediation
References
Related Vulnerabilities
WordPress Plugin YITH WooCommerce Badge Management Security Bypass (1.3.19)
OpenSSL NULL Pointer Dereference Vulnerability (CVE-2009-1386)
WordPress Plugin Hana Flv Player Cross-Site Scripting (3.1.3)
WordPress 3.8.x Same Origin Method Execution (SOME) Vulnerability (3.8 - 3.8.13)
Grafana Exposure of Sensitive Information to an Unauthorized Actor Vulnerability (CVE-2020-12459)