Piwigo Improper Neutralization of Input During Web Page Generation (Cross-site Scripting) Vulnerability - CVE-2019-13364 - Vulnerability Database

Piwigo Improper Neutralization of Input During Web Page Generation (Cross-site Scripting) Vulnerability - CVE-2019-13364

Critical
Reference: CVE-2019-13364
Title: Piwigo Improper Neutralization of Input During Web Page Generation (Cross-site Scripting) Vulnerability
Overview:

admin.phppageaccount_billing in Piwigo 2.9.5 has XSS via the vatamp95number billingamp95name company or billingamp95address parameter. This is exploitable via CSRF.