First published: Thu Feb 10 2022(Updated: )
Cross Site Scripting (XSS) vulnerability exists in Piwigo 12.x via the pwg_activity function in include/functions.inc.php.
Credit: cve@mitre.org
Affected Software | Affected Version | How to fix |
---|---|---|
Piwigo Piwigo | >=12.0.0<=12.1.0 |
Sign up to SecAlerts for real-time vulnerability data matched to your software, aggregated from hundreds of sources.
The vulnerability ID is CVE-2021-45357.
The affected software is Piwigo version 12.x.
The severity of CVE-2021-45357 is medium.
The Cross-Site Scripting (XSS) vulnerability occurs via the pwg_activity function in include/functions.inc.php.
Yes, a fix for this vulnerability is available. Update Piwigo to version 12.1.1 or later.