Description
In Piwigo 11.5.0, there exists a persistent cross-site scripting in the single mode function through /admin.php?page=batch_manager&mode=unit.
Remediation
References
Related Vulnerabilities
WordPress Plugin Enable Media Replace Directory Traversal (3.6.3)
Drupal Core 5.x Multiple Vulnerabilities (5.0 - 5.7)
Oracle JRE CVE-2013-2452 Vulnerability (CVE-2013-2452)
WordPress 2.0.2 Username Remote PHP Code Injection Vulnerability (0.6.2 - 2.0.2)
WordPress Plugin TheCartPress eCommerce Shopping Cart Order Information Security Bypass (1.1.9.2)