CVE-2014-3900: XSS
Published Aug 17, 2014
·Updated
Cross-site scripting (XSS) vulnerability in admin/picturemodify.php in the photo-edit subsystem in Piwigo 2.6.3 and earlier allows remote attackers to inject arbitrary web script or HTML via the associate[] field, a different vulnerability than CVE-2014-4649.
Affected Software
4 affected components
Piwigo piwigo<=2.6.3
Piwigo piwigo=2.6.0
Piwigo piwigo=2.6.1
Piwigo piwigo=2.6.2
Event History
Aug 17, 2014
CVE Published
via MITRE·06:00 PM
Data Sourced
via MITRE·06:00 PM
Description
Frequently Asked Questions
1
What is the severity of CVE-2014-3900?
The CVE-2014-3900 vulnerability is classified as a cross-site scripting (XSS) vulnerability with a medium severity level.
2
How do I fix CVE-2014-3900?
To fix CVE-2014-3900, update Piwigo to a version later than 2.6.3.
3
Which versions of Piwigo are affected by CVE-2014-3900?
CVE-2014-3900 affects Piwigo versions 2.6.3 and earlier.
4
What type of vulnerability is CVE-2014-3900?
CVE-2014-3900 is a cross-site scripting (XSS) vulnerability allowing remote attackers to inject arbitrary web scripts or HTML.
5
Where is the vulnerability located in CVE-2014-3900?
CVE-2014-3900 is located in the admin/picture_modify.php file within the photo-edit subsystem of Piwigo.