Description
Piwigo 2.10.1 has stored XSS via the file parameter in a /ws.php request because of the pwg.images.setInfo function.
Remediation
References
Related Vulnerabilities
WordPress Plugin Community Events SQL Injection (1.3.5)
OpenSSL Improper Authentication Vulnerability (CVE-2010-4252)
Seo Panel Observable Discrepancy Vulnerability (CVE-2024-22647)
Atlassian Confluence Improper Input Validation Vulnerability (CVE-2018-13389)
WordPress Plugin Drag and Drop Multiple File Upload-Contact Form 7 Security Bypass (1.3.6.4)