Description
admin.php?page=account_billing in Piwigo 2.9.5 has XSS via the vat_number, billing_name, company, or billing_address parameter. This is exploitable via CSRF.
Remediation
References
Related Vulnerabilities
phpMyAdmin Other Vulnerability (CVE-2007-0341)
WordPress Plugin Photospace Responsive Gallery Unspecified Vulnerability (1.1.7)
WordPress Plugin CM Answers Cross-Site Scripting (2.6.1)
WordPress Plugin Happy Addons for Elementor Cross-Site Scripting (2.23.0)
phpMyAdmin Improper Input Validation Vulnerability (CVE-2011-2719)