First published: Thu Mar 26 2020(Updated: )
Piwigo 2.10.1 has stored XSS via the file parameter in a /ws.php request because of the pwg.images.setInfo function.
Credit: cve@mitre.org
Affected Software | Affected Version | How to fix |
---|---|---|
Piwigo Piwigo | =2.10.1 |
Sign up to SecAlerts for real-time vulnerability data matched to your software, aggregated from hundreds of sources.
The vulnerability ID for Piwigo 2.10.1 is CVE-2020-9467.
The severity level of CVE-2020-9467 is medium (5.4).
The affected software version for CVE-2020-9467 is Piwigo 2.10.1.
Piwigo 2.10.1 has a stored XSS vulnerability via the file parameter in a /ws.php request because of the pwg.images.setInfo function.
To fix CVE-2020-9467, it is recommended to update Piwigo to a version beyond 2.10.1 and apply any available patches.