6.8
CVSSv2

CVE-2019-13363

Published: 13/09/2019 Updated: 28/02/2023
CVSS v2 Base Score: 6.8 | Impact Score: 6.4 | Exploitability Score: 8.6
CVSS v3 Base Score: 9.6 | Impact Score: 6 | Exploitability Score: 2.8
VMScore: 609
Vector: AV:N/AC:M/Au:N/C:P/I:P/A:P

Vulnerability Summary

admin.php?page=notification_by_mail in Piwigo 2.9.5 has XSS via the nbm_send_html_mail, nbm_send_mail_as, nbm_send_detailed_content, nbm_complementary_mail_content, nbm_send_recent_post_dates, or param_submit parameter. This is exploitable via CSRF.

Vulnerability Trend

Vulnerable Product Search on Vulmon Subscribe to Product

piwigo piwigo 2.9.5

Exploits

GilaCMS version 1115 suffers from cross site request forgery and cross site scripting vulnerabilities ...
Piwigo version 295 suffers from cross site request forgery and cross site scripting vulnerabilities ...

Mailing Lists

<!--X-Body-Begin--> <!--X-User-Header--> Full Disclosure mailing list archives <!--X-User-Header-End--> <!--X-TopPNI--> By Date By Thread </form> <!--X-TopPNI-End--> <!--X-MsgBody--> <!--X-Subject-Header-Begin--> GilaCMS - CVE-2019-13364 CVE-2019-13363 <!--X-Subject-Header-End--> <!--X-Head-of-Message--> From: Rodolfo Augusto d ...