3.5
CVSSv2

CVE-2020-9467

Published: 26/03/2020 Updated: 24/05/2022
CVSS v2 Base Score: 3.5 | Impact Score: 2.9 | Exploitability Score: 6.8
CVSS v3 Base Score: 5.4 | Impact Score: 2.7 | Exploitability Score: 2.3
VMScore: 312
Vector: AV:N/AC:M/Au:S/C:N/I:P/A:N

Vulnerability Summary

Piwigo 2.10.1 has stored XSS via the file parameter in a /ws.php request because of the pwg.images.setInfo function.

Vulnerability Trend

Vulnerable Product Search on Vulmon Subscribe to Product

piwigo piwigo 2.10.1

Exploits

Piwigo version 2101 suffers from a cross site scripting vulnerability ...