vendor:
Piwigo
by:
Okan Kurtulus
5.5
CVSS
MEDIUM
Stored Cross-Site Scripting (XSS)
79
CWE
Product Name: Piwigo
Affected Version From: 13.7.2000
Affected Version To: 13.7.2000
Patch Exists: NO
Related CWE:
CPE: piwigo
Platforms Tested: Ubuntu 22.04
2023
Piwigo v13.7.0 – Stored Cross-Site Scripting (XSS) (Authenticated)
The Piwigo version 13.7.0 is vulnerable to a stored cross-site scripting (XSS) attack. An authenticated user with the privilege to upload photos can inject malicious code into the 'Description' field of the photo editing screen. When the photo is viewed on the homepage, the XSS payload is executed.
Mitigation:
To mitigate this vulnerability, it is recommended to validate and sanitize user input before displaying it on web pages. The Piwigo development team should release a patch addressing this issue.