Zenphoto Improper Neutralization of Input During Web Page Generation (Cross-site Scripting) Vulnerability - CVE-2022-44449 - Vulnerability Database

Zenphoto Improper Neutralization of Input During Web Page Generation (Cross-site Scripting) Vulnerability - CVE-2022-44449

Medium
Reference: CVE-2022-44449
Title: Zenphoto Improper Neutralization of Input During Web Page Generation (Cross-site Scripting) Vulnerability
Overview:

Stored cross-site scripting vulnerability in Zenphoto versions prior to 1.6 allows remote a remote authenticated attacker with an administrative privilege to inject an arbitrary script.