CVE-2024-46333

CVSS 3.1 Score 4.8 of 10 (medium)

Details

Published Sep 27, 2024
Updated: Sep 30, 2024
CWE ID 79

Summary

CVE-2024-46333 is an authenticated cross-site scripting (XSS) vulnerability affecting Piwigo version 14.5.0. This issue permits attackers to inject arbitrary web scripts or HTML into the Album Name parameter during the Add Album function. Successful exploitation could lead to unintended execution of malicious code within the user's browser or on the affected system, posing a significant security risk. Authenticated users with the ability to add albums can be targeted, allowing attackers to manipulate content, steal sensitive data, or carry out other malicious activities. Updating to the latest Piwigo version is recommended to mitigate this vulnerability.

Ligh bulbPrevent cyber attacks with Recorded Future by prioritizing and patching critical vulnerabilities being exploited by threat actors targeting your industry. Book your demo to learn more.

Share