PT-2026-79823 · Piwigo · Piwigo
CVSS v3.1
3.1
Low
| Vector | AV:N/AC:H/PR:N/UI:R/S:U/C:N/I:L/A:N |
Name of the Vulnerable Software and Affected Versions
Piwigo version 16.3.0
Description
A remote cross-site scripting issue exists within the Public Authentication Page component. The flaw allows for the manipulation of the
lang argument to execute malicious scripts. This attack is characterized by high complexity and is considered difficult to exploit.Recommendations
Upgrade to version 16.4.0.
Exploit
Fix
XSS
Code Injection
Found an issue in the description? Have something to add? Feel free to write us 👾
Related Identifiers
Affected Products
Piwigo