Zenphoto Improper Neutralization of Input During Web Page Generation (Cross-site Scripting) Vulnerability - CVE-2015-5592 - Vulnerability Database

Zenphoto Improper Neutralization of Input During Web Page Generation (Cross-site Scripting) Vulnerability - CVE-2015-5592

Medium
Reference: CVE-2015-5592
Title: Zenphoto Improper Neutralization of Input During Web Page Generation (Cross-site Scripting) Vulnerability
Overview:

Incomplete blacklist in sanitize_string in Zenphoto before 1.4.9 allows remote attackers to conduct cross-site scripting (XSS) attacks.