6.8
CVSSv2

CVE-2019-13364

Published: 13/09/2019 Updated: 28/02/2023
CVSS v2 Base Score: 6.8 | Impact Score: 6.4 | Exploitability Score: 8.6
CVSS v3 Base Score: 9.6 | Impact Score: 6 | Exploitability Score: 2.8
VMScore: 609
Vector: AV:N/AC:M/Au:N/C:P/I:P/A:P

Vulnerability Summary

admin.php?page=account_billing in Piwigo 2.9.5 has XSS via the vat_number, billing_name, company, or billing_address parameter. This is exploitable via CSRF.

Vulnerability Trend

Vulnerable Product Search on Vulmon Subscribe to Product

piwigo piwigo 2.9.5

Exploits

GilaCMS version 1115 suffers from cross site request forgery and cross site scripting vulnerabilities ...
Piwigo version 295 suffers from cross site request forgery and cross site scripting vulnerabilities ...

Mailing Lists

<!--X-Body-Begin--> <!--X-User-Header--> Full Disclosure mailing list archives <!--X-User-Header-End--> <!--X-TopPNI--> By Date By Thread </form> <!--X-TopPNI-End--> <!--X-MsgBody--> <!--X-Subject-Header-Begin--> GilaCMS - CVE-2019-13364 CVE-2019-13363 <!--X-Subject-Header-End--> <!--X-Head-of-Message--> From: Rodolfo Augusto d ...