CVE-2020-9467: XSS
Published Mar 26, 2020
·Updated
Piwigo 2.10.1 has stored XSS via the file parameter in a /ws.php request because of the pwg.images.setInfo function.
Affected Software
1 affected component
Piwigo piwigo=2.10.1
Remediation
Patch Available
Event History
Mar 26, 2020
CVE Published
via MITRE·07:09 PM
Data Sourced
via MITRE·07:09 PM
Description
Data Sourced
via NVD·08:15 PM
RemedyDescriptionSeverityWeaknessAffected Software
Frequently Asked Questions
1
What is the vulnerability ID for Piwigo 2.10.1?
The vulnerability ID for Piwigo 2.10.1 is CVE-2020-9467.
2
What is the severity level of CVE-2020-9467?
The severity level of CVE-2020-9467 is medium (5.4).
3
What is the affected software version for CVE-2020-9467?
The affected software version for CVE-2020-9467 is Piwigo 2.10.1.
4
What is the description of CVE-2020-9467?
Piwigo 2.10.1 has a stored XSS vulnerability via the file parameter in a /ws.php request because of the pwg.images.setInfo function.
5
How can I fix CVE-2020-9467?
To fix CVE-2020-9467, it is recommended to update Piwigo to a version beyond 2.10.1 and apply any available patches.