This is a writeup detailing a stored XSS vulnerability in Piwigo 2.5.2, where malicious JavaScript can be injected into photo metadata fields (Title, Author, Tags, Description) and executed when viewed in the gallery.
Classification
Writeup 90%
Attack Type
Xss
Complexity
Trivial
Reliability
Reliable
Target:Piwigo 2.5.2
Auth required
Prerequisites:Authenticated access to Piwigo admin panel · Ability to upload/edit photos