CVE-2019-13364: XSS
Published Sep 13, 2019
·Updated
admin.php?page=accountbilling in Piwigo 2.9.5 has XSS via the vat_number, billing_name, company, or billing_address parameter. This is exploitable via CSRF.
Affected Software
1 affected component
Piwigo piwigo=2.9.5
Event History
Sep 13, 2019
CVE Published
via MITRE·12:24 PM
Data Sourced
via MITRE·12:24 PM
Description
Frequently Asked Questions
1
What is the severity of CVE-2019-13364?
The severity of CVE-2019-13364 is critical with a score of 9.6.
2
How does CVE-2019-13364 affect Piwigo?
CVE-2019-13364 affects Piwigo 2.9.5.
3
What is the vulnerability type of CVE-2019-13364?
The vulnerability type of CVE-2019-13364 is XSS (Cross-Site Scripting).
4
How can CVE-2019-13364 be exploited?
CVE-2019-13364 can be exploited via CSRF (Cross-Site Request Forgery).
5
Is there a fix available for CVE-2019-13364?
Yes, a fix is available for CVE-2019-13364. It is recommended to update to a version of Piwigo that is not affected by this vulnerability.