Description
Cross-site scripting (XSS) vulnerability in function.php in Zenphoto 1.1.7 allows remote attackers to inject arbitrary web script or HTML via unspecified vectors in the "request logging" feature. NOTE: the provenance of this information is unknown; the details are obtained solely from third party information.
Remediation
References
Related Vulnerabilities
WordPress Plugin Livefyre Comments 3 Cross-Site Scripting (4.1.4)
WordPress Plugin Simple Contact Info Arbitrary File Deletion (1.1.9)
WordPress 'templates.php' Cross-Site Scripting Vulnerability (0.6.2 - 2.1)
PHP Exposure of Sensitive Information to an Unauthorized Actor Vulnerability (CVE-2010-2531)
Jboss EAP Deserialization of Untrusted Data Vulnerability (CVE-2018-14720)