First published: Fri Sep 13 2019(Updated: )
admin.php?page=account_billing in Piwigo 2.9.5 has XSS via the vat_number, billing_name, company, or billing_address parameter. This is exploitable via CSRF.
Credit: cve@mitre.org
Affected Software | Affected Version | How to fix |
---|---|---|
Piwigo Piwigo | =2.9.5 |
Sign up to SecAlerts for real-time vulnerability data matched to your software, aggregated from hundreds of sources.
The severity of CVE-2019-13364 is critical with a score of 9.6.
CVE-2019-13364 affects Piwigo 2.9.5.
The vulnerability type of CVE-2019-13364 is XSS (Cross-Site Scripting).
CVE-2019-13364 can be exploited via CSRF (Cross-Site Request Forgery).
Yes, a fix is available for CVE-2019-13364. It is recommended to update to a version of Piwigo that is not affected by this vulnerability.