Piwigo Improper Neutralization of Input During Web Page Generation (Cross-site Scripting) Vulnerability - CVE-2018-7722 - Vulnerability Database
Piwigo Improper Neutralization of Input During Web Page Generation (Cross-site Scripting) Vulnerability - CVE-2018-7722
Medium
Reference:
CVE-2018-7722
Title:
Piwigo Improper Neutralization of Input During Web Page Generation (Cross-site Scripting) Vulnerability
Overview:
The management panel in Piwigo 2.9.3 has stored XSS via the name parameter in a /ws.phpformatjson request. CSRF exploitation related to CVE-2017-10681 may be possible.