Description
Piwigo 2.10.1 has stored XSS via the file parameter in a /ws.php request because of the pwg.images.setInfo function.
Remediation
References
Related Vulnerabilities
Undertow Missing Authorization Vulnerability (CVE-2019-10184)
Apache HTTP Server Resource Management Errors Vulnerability (CVE-2014-3523)
WordPress Plugin Video Conferencing with Zoom Information Disclosure (3.8.16)
Oracle JRE CVE-2013-5797 Vulnerability (CVE-2013-5797)
Apache Tomcat Permissions, Privileges, and Access Controls Vulnerability (CVE-2011-3190)