CVE-2018-14478: XSS
Published May 7, 2019
·Updated
ecard.php in Coppermine Photo Gallery (CPG) 1.5.46 has XSS via the sendername, recipientemail, greetings, or recipientname parameter.
Affected Software
1 affected component
Coppermine-gallery Coppermine Photo Gallery=1.5.46
Event History
May 7, 2019
CVE Published
via MITRE·05:41 PM
Data Sourced
via MITRE·05:41 PM
Description
Frequently Asked Questions
1
What is the severity of CVE-2018-14478?
CVE-2018-14478 is classified as a high severity Cross-Site Scripting (XSS) vulnerability.
2
How do I fix CVE-2018-14478?
To fix CVE-2018-14478, you should upgrade to a patched version of Coppermine Photo Gallery that addresses this XSS vulnerability.
3
What parameters are affected by CVE-2018-14478?
CVE-2018-14478 affects the sender_name, recipient_email, greetings, and recipient_name parameters in ecard.php.
4
Can CVE-2018-14478 lead to data theft?
Yes, CVE-2018-14478 can lead to data theft or unauthorized actions due to its XSS nature.
5
Is Coppermine Photo Gallery 1.5.46 still secure?
No, Coppermine Photo Gallery 1.5.46 is not secure due to the existence of CVE-2018-14478.