Piwigo Improper Neutralization of Input During Web Page Generation (Cross-site Scripting) Vulnerability - CVE-2018-5692 - Vulnerability Database

Piwigo Improper Neutralization of Input During Web Page Generation (Cross-site Scripting) Vulnerability - CVE-2018-5692

Medium
Reference: CVE-2018-5692
Title: Piwigo Improper Neutralization of Input During Web Page Generation (Cross-site Scripting) Vulnerability
Overview:

Piwigo v2.8.2 has XSS via the tab to section mode installstatus and display parameters of the admin.php file.