Description Piwigo 2.10.1 has stored XSS via the file parameter in a /ws.php request because of the pwg.images.setInfo function. Remediation References CVE-2020-9467 Related Vulnerabilities Oracle JRE CVE-2014-0464 Vulnerability (CVE-2014-0464) WordPress Plugin Post SMTP-WP SMTP with Email Logs & Mobile App for Failure Alerts-Any SMTP Plus Gmail SMTP, Office 365, Brevo, Mailgun, Amazon SES, Postmark Cross-Site Scripting (2.8.7) MediaWiki Resource Management Errors Vulnerability (CVE-2015-8003) WordPress Plugin W4 Post List Multiple Vulnerabilities (2.4.5) MySQL Cryptographic Issues Vulnerability (CVE-2003-1480) Severity Medium Classification CVE-2020-9467 CWE-707 CVSS:3.1/AV:N/AC:L/PR:L/UI:R/S:C/C:L/I:L/A:N Tags Missing Update Known Vulnerabilities