Description
The sanitize_string function in ZenPhoto before 1.4.9 utilized the html_entity_decode function after input sanitation, which might allow remote attackers to perform a cross-site scripting (XSS) via a crafted string.
Remediation
References
Related Vulnerabilities
Perl Out-of-bounds Write Vulnerability (CVE-2018-6797)
PHP NULL Pointer Dereference Vulnerability (CVE-2016-7131)
OpenSSL Resource Management Errors Vulnerability (CVE-2008-1678)
MySQL CVE-2021-35641 Vulnerability (CVE-2021-35641)
OpenSSL Use of a Broken or Risky Cryptographic Algorithm Vulnerability (CVE-2018-0737)