Stored Cross-Site Scripting Vulnerability in Piwigo by Piwigo
CVE-2022-48007
5.4MEDIUM
What is CVE-2022-48007?
A stored cross-site scripting vulnerability exists in Piwigo v13.4.0, specifically within the identification.php file. This flaw enables attackers to inject arbitrary web scripts or HTML into the User-Agent field. If successfully exploited, it can lead to unauthorized actions performed on behalf of users, potentially compromising user accounts and allowing attackers to manipulate content or gain sensitive information.