Piwigo Improper Neutralization of Input During Web Page Generation (Cross-site Scripting) Vulnerability - CVE-2018-7722 - Vulnerability Database

Piwigo Improper Neutralization of Input During Web Page Generation (Cross-site Scripting) Vulnerability - CVE-2018-7722

Medium
Reference: CVE-2018-7722
Title: Piwigo Improper Neutralization of Input During Web Page Generation (Cross-site Scripting) Vulnerability
Overview:

The management panel in Piwigo 2.9.3 has stored XSS via the name parameter in a /ws.phpformatjson request. CSRF exploitation related to CVE-2017-10681 may be possible.