Description
Cross-site scripting (XSS) vulnerability in function.php in Zenphoto 1.1.7 allows remote attackers to inject arbitrary web script or HTML via unspecified vectors in the "request logging" feature. NOTE: the provenance of this information is unknown; the details are obtained solely from third party information.
Remediation
References
Related Vulnerabilities
WordPress Plugin Lightbox Jquery Possible Remote Code Execution (0.24)
Dolibarr Unrestricted Upload of File with Dangerous Type Vulnerability (CVE-2020-14209)
MediaWiki Incorrect Permission Assignment for Critical Resource Vulnerability (CVE-2022-47927)
e107 Inadequate Encryption Strength Vulnerability (CVE-2021-27885)