Description
The sanitize_string function in ZenPhoto before 1.4.9 utilized the html_entity_decode function after input sanitation, which might allow remote attackers to perform a cross-site scripting (XSS) via a crafted string.
Remediation
References
Related Vulnerabilities
MediaWiki Use of a Broken or Risky Cryptographic Algorithm Vulnerability (CVE-2021-31556)
WordPress 6.5.x Multiple Vulnerabilities (6.5 - 6.5.4)
WordPress Plugin IP Blacklist Cloud Arbitrary File Disclosure (3.42)
Jenkins Exposure of Sensitive Information to an Unauthorized Actor Vulnerability (CVE-2018-1000192)