First published: Tue Jun 14 2022(Updated: )
In Piwigo 11.5.0, there exists a persistent cross-site scripting in the single mode function through /admin.php?page=batch_manager&mode=unit.
Credit: cve@mitre.org
Affected Software | Affected Version | How to fix |
---|---|---|
Piwigo Piwigo | =11.5.0 |
Sign up to SecAlerts for real-time vulnerability data matched to your software, aggregated from hundreds of sources.
The vulnerability ID for this issue in Piwigo is CVE-2021-40678.
The severity of CVE-2021-40678 is medium with a CVSS score of 5.4.
Piwigo version 11.5.0 is affected by CVE-2021-40678.
The CWE category for CVE-2021-40678 is CWE-79 (Cross-Site Scripting).
At the moment, there is no known fix available for CVE-2021-40678. It is recommended to update to a patched version once the fix is released.