Piwigo Improper Neutralization of Input During Web Page Generation (Cross-site Scripting) Vulnerability - CVE-2021-40678 - Vulnerability Database
Piwigo Improper Neutralization of Input During Web Page Generation (Cross-site Scripting) Vulnerability - CVE-2021-40678
Medium
Reference:
CVE-2021-40678
Title:
Piwigo Improper Neutralization of Input During Web Page Generation (Cross-site Scripting) Vulnerability
Overview:
In Piwigo 11.5.0 there exists a persistent cross-site scripting in the single mode function through /admin.phppagebatch_managerampmodeunit.