CVE-2024-46333
CVSS 3.1 Score 4.8 of 10 (medium)
Details
Summary
CVE-2024-46333 is an authenticated cross-site scripting (XSS) vulnerability affecting Piwigo version 14.5.0. This issue permits attackers to inject arbitrary web scripts or HTML into the Album Name parameter during the Add Album function. Successful exploitation could lead to unintended execution of malicious code within the user's browser or on the affected system, posing a significant security risk. Authenticated users with the ability to add albums can be targeted, allowing attackers to manipulate content, steal sensitive data, or carry out other malicious activities. Updating to the latest Piwigo version is recommended to mitigate this vulnerability.
Prevent cyber attacks with Recorded Future by prioritizing and patching critical vulnerabilities being exploited by threat actors targeting your industry. Book your demo to learn more.
Affected Vendors
- Piwigo