CVE-2021-40678: XSS
Published Jun 14, 2022
·Updated
In Piwigo 11.5.0, there exists a persistent cross-site scripting in the single mode function through /admin.php?page=batchmanager&mode=unit.
Affected Software
1 affected component
Piwigo piwigo=11.5.0
Event History
Jun 14, 2022
CVE Published
via MITRE·12:16 PM
Data Sourced
via MITRE·12:16 PM
Description
Frequently Asked Questions
1
What is the vulnerability ID for this issue in Piwigo?
The vulnerability ID for this issue in Piwigo is CVE-2021-40678.
2
What is the severity of CVE-2021-40678?
The severity of CVE-2021-40678 is medium with a CVSS score of 5.4.
3
What is the affected version of Piwigo?
Piwigo version 11.5.0 is affected by CVE-2021-40678.
4
What is the CWE category for this vulnerability?
The CWE category for CVE-2021-40678 is CWE-79 (Cross-Site Scripting).
5
Is there a fix available for CVE-2021-40678?
At the moment, there is no known fix available for CVE-2021-40678. It is recommended to update to a patched version once the fix is released.