CVE-2024-46606: XSS
A cross-site scripting (XSS) vulnerability in the component /admin.php?page=photo of Piwigo v14.5.0 allows attackers to execute arbitrary web scripts or HTML via a crafted payload injected into the Description field.
Affected Software
Event History
Frequently Asked Questions
What is the severity of CVE-2024-46606?
CVE-2024-46606 has a severe impact as it allows cross-site scripting (XSS) attacks to execute arbitrary scripts.
How do I fix CVE-2024-46606?
To fix CVE-2024-46606, ensure that user inputs are properly sanitized and encoded in the Piwigo application.
What components are affected by CVE-2024-46606?
CVE-2024-46606 specifically affects the /admin.php?page=photo component of Piwigo version 14.5.0.
Can CVE-2024-46606 lead to data breaches?
Yes, CVE-2024-46606 can potentially lead to data breaches by allowing attackers to inject malicious scripts.
Is CVE-2024-46606 present in versions of Piwigo other than 14.5.0?
Currently, CVE-2024-46606 is identified in Piwigo version 14.5.0 and there are no indications it affects earlier or later versions.