Description
Cross-site scripting (XSS) vulnerability in admin/plugin.php in Piwigo through 2.8.3 allows remote attackers to inject arbitrary web script or HTML via a crafted filename that is mishandled in a certain error case.
Remediation
References
Related Vulnerabilities
WordPress Plugin kk Star Ratings 'root' Parameter Remote File Include (1.7)
MediaWiki Exposure of Sensitive Information to an Unauthorized Actor Vulnerability (CVE-2016-6332)
WordPress Plugin Theme My Login Security Bypass (6.4.6)
WordPress Plugin ShiftNav-Responsive Mobile Menu Cross-Site Scripting (1.7.1)
Oracle Database Server CVE-2010-4420 Vulnerability (CVE-2010-4420)