Description
Piwigo 2.10.1 has stored XSS via the file parameter in a /ws.php request because of the pwg.images.setInfo function.
Remediation
References
Related Vulnerabilities
WordPress Plugin Shopping Cart & eCommerce Store Arbitrary File Upload (3.0.8)
Squid Out-of-bounds Read Vulnerability (CVE-2021-28116)
WebLogic Improper Check for Unusual or Exceptional Conditions Vulnerability (CVE-2021-27568)
Envoy Proxy Loop with Unreachable Exit Condition ('Infinite Loop') Vulnerability (CVE-2019-18836)
WordPress Plugin UPM Polls 'PID' Parameter SQL Injection (1.0.4)