Piwigo Improper Neutralization of Input During Web Page Generation (Cross-site Scripting) Vulnerability - CVE-2018-7723 - Vulnerability Database

Piwigo Improper Neutralization of Input During Web Page Generation (Cross-site Scripting) Vulnerability - CVE-2018-7723

Medium
Reference: CVE-2018-7723
Title: Piwigo Improper Neutralization of Input During Web Page Generation (Cross-site Scripting) Vulnerability
Overview:

The management panel in Piwigo 2.9.3 has stored XSS via the virtual_name parameter in a /admin.phppagecat_list request a different issue than CVE-2017-9836. CSRF exploitation related to CVE-2017-10681 may be possible.