Piwigo Improper Neutralization of Input During Web Page Generation (Cross-site Scripting) Vulnerability - CVE-2019-13364 - Vulnerability Database
Piwigo Improper Neutralization of Input During Web Page Generation (Cross-site Scripting) Vulnerability - CVE-2019-13364
Critical
Reference:
CVE-2019-13364
Title:
Piwigo Improper Neutralization of Input During Web Page Generation (Cross-site Scripting) Vulnerability
Overview:
admin.phppageaccount_billing in Piwigo 2.9.5 has XSS via the vatamp95number billingamp95name company or billingamp95address parameter. This is exploitable via CSRF.