CVE-2020-22150: XSS
Published Jul 21, 2021
·Updated
A cross site scripting (XSS) vulnerability in /admin.php?page=permalinks of Piwigo 2.10.1 allows attackers to execute arbitrary web scripts or HTML.
Affected Software
1 affected component
Piwigo piwigo=2.10.1
Event History
Jul 21, 2021
CVE Published
via MITRE·04:07 PM
Data Sourced
via MITRE·04:07 PM
Description
Frequently Asked Questions
1
What is the vulnerability ID for this cross-site scripting (XSS) vulnerability?
The vulnerability ID for this cross-site scripting (XSS) vulnerability is CVE-2020-22150.
2
What is the affected software?
The affected software is Piwigo version 2.10.1.
3
What is the severity of CVE-2020-22150?
The severity of CVE-2020-22150 is medium, with a CVSS score of 6.1.
4
How can attackers exploit CVE-2020-22150?
Attackers can exploit CVE-2020-22150 by executing arbitrary web scripts or HTML.
5
Is there a fix available for CVE-2020-22150?
Yes, a fix is available. It is recommended to update Piwigo to a version that addresses this vulnerability.