Cross-Site Scripting Vulnerability in Zenphoto Image Processor
CVE-2015-2948

Currently unrated

Key Information:

Vendor

Zenphoto

Status
Vendor
CVE Published:
31 May 2015

What is CVE-2015-2948?

A cross-site scripting (XSS) vulnerability exists in the image processor of Zenphoto prior to version 1.4.8. This flaw permits remote attackers to inject malicious web scripts or HTML through unspecified techniques, potentially compromising user interactions and data integrity.

References

Timeline

  • Vulnerability published

  • Vulnerability Reserved

.