Description
The sanitize_string function in ZenPhoto before 1.4.9 utilized the html_entity_decode function after input sanitation, which might allow remote attackers to perform a cross-site scripting (XSS) via a crafted string.
Remediation
References
Related Vulnerabilities
WordPress Plugin Stream Cross-Site Scripting (3.0.5)
MySQL CVE-2020-2790 Vulnerability (CVE-2020-2790)
WordPress Plugin Ticketrilla:Client PHP Object Injection (1.0.1)
PHP Other Vulnerability (CVE-2014-4670)
Werkzeug WSGI Allocation of Resources Without Limits or Throttling Vulnerability (CVE-2023-25577)