VulnerabilityModified
CVE-2023-53915
Zenphoto 1.6 contains a stored cross-site scripting vulnerability that allows authenticated attackers to inject malicious scripts by inserting HTML content into album descriptions.
MEDIUM 5.1EPSS 0.31%
Does this matter?
Lower severity and a low EPSS score (0.31%). Track it; it rarely justifies an emergency change on its own.
Description
Zenphoto 1.6 contains a stored cross-site scripting vulnerability that allows authenticated attackers to inject malicious scripts by inserting HTML content into album descriptions. Attackers can create albums with malicious iframe or script tags in the description field that execute when users view the album page.
- CVSS 4.0
- 5.1 MEDIUMCVSS:4.0/AV:N/AC:L/AT:N/PR:L/UI:P/VC:L/VI:L/VA:N/SC:L/SI:L/SA:N/E:X/CR:X/IR:X/AR:X/MAV:X/MAC:X/MAT:X/MPR:X/MUI:X/MVC:X/M
- EPSS
- 0.31% probability · 24th percentile
- CISA KEV
- Not listed
- Weakness
- CWE-79
- Affected
- zenphoto/zenphoto
- Source
- disclosure@vulncheck.com
References
- https://www.exploit-db.com/exploits/51485Exploit, Third Party Advisory, VDB Entry
- https://www.vulncheck.com/advisories/zenphoto-stored-cross-site-scripting-via-album-descriptionExploit, Third Party Advisory
- https://www.zenphoto.org/news/zenphoto-1.6/Release Notes
- https://www.exploit-db.com/exploits/51485Exploit, Third Party Advisory, VDB Entry
Source: NVD record, EPSS from FIRST.org, KEV from CISA. Refreshed daily.