Description
ecard.php in Coppermine Photo Gallery (CPG) 1.5.46 has XSS via the sender_name, recipient_email, greetings, or recipient_name parameter.
Remediation
References
Related Vulnerabilities
WordPress Plugin Shopping Cart & eCommerce Store Multiple Security Bypass Vulnerabilities (3.0.20)
WordPress Plugin GD Star Rating 'export.php' Security Bypass (1.9.18)
WordPress Plugin WP Shop Multiple SQL Injection Vulnerabilities (3.4.3.15)
WordPress Plugin WP-VR-view-Add Photo Sphere, 360 video to WordPress Cross-Site Scripting (1.6)