Description
The Batch Manager component of Piwigo 2.9.2 is vulnerable to Persistent Cross Site Scripting via tags-* array parameters in an admin.php?page=batch_manager&mode=unit request. An attacker can exploit this to hijack a client's browser along with the data stored in it.
Remediation
References
Related Vulnerabilities
WordPress Plugin Google XML Sitemaps Cross-Site Scripting (4.0.8)
WordPress Plugin I Recommend This SQL Injection (3.7.7)
Oracle JRE CVE-2012-5071 Vulnerability (CVE-2012-5071)
SharePoint CVE-2024-38018 Vulnerability (CVE-2024-38018)
Atlassian Jira Cross-Site Request Forgery (CSRF) Vulnerability (CVE-2019-20415)