Description
Piwigo v2.8.2 has XSS via the `tab`, `to`, `section`, `mode`, `installstatus`, and `display` parameters of the `admin.php` file.
Remediation
References
Related Vulnerabilities
WordPress Plugin Caldera Forms-More Than Contact Forms Arbitrary File Disclosure (1.8.1)
PostgreSQL Permissions, Privileges, and Access Controls Vulnerability (CVE-2013-1903)
Oracle Application Server Improper Authentication Vulnerability (CVE-2002-0563)
concrete5 Server-Side Request Forgery (SSRF) Vulnerability (CVE-2018-13790)