CVE-2020-8089: XSS
Published Feb 10, 2020
·Updated
Piwigo 2.10.1 is affected by stored XSS via the Group Name Field to the grouplist page.
Affected Software
1 affected component
Piwigo piwigo=2.10.1
Event History
Feb 10, 2020
CVE Published
via MITRE·03:12 PM
Data Sourced
via MITRE·03:12 PM
Description
Data Sourced
via NVD·04:15 PM
DescriptionSeverityWeaknessAffected Software
Frequently Asked Questions
1
What is the vulnerability ID for Piwigo 2.10.1?
The vulnerability ID for Piwigo 2.10.1 is CVE-2020-8089.
2
What is the severity of CVE-2020-8089?
The severity of CVE-2020-8089 is medium with a CVSS score of 5.4.
3
How does CVE-2020-8089 affect Piwigo 2.10.1?
CVE-2020-8089 affects Piwigo 2.10.1 through stored XSS via the Group Name Field on the group_list page.
4
How can I fix CVE-2020-8089 in Piwigo 2.10.1?
To fix CVE-2020-8089 in Piwigo 2.10.1, update to a version that includes a patch for the vulnerability.
5
Where can I find more information about CVE-2020-8089?
More information about CVE-2020-8089 can be found at the following references: [GitHub Issue #1150](https://github.com/Piwigo/Piwigo/issues/1150) and [Piwigo Forum](https://piwigo.org/forum/viewforum.php?id=23).