Cross Site Scripting in Piwigo Admin Tools Plugin
CVE-2023-51790
6.1MEDIUM
What is CVE-2023-51790?
A cross site scripting vulnerability exists in the Admin Tools component of Piwigo version 14.0.0. This flaw allows a remote attacker to inject malicious scripts by manipulating the 'lang' parameter. If successfully exploited, it could enable the attacker to access sensitive information, posing significant risks to affected users and potentially compromising the integrity of the system.