Security Advisory

CVE-2015-5594

CVE vulnerability detail - eXtreme Datacenter Security Operations

Published 2017-07-25 18:00:00
Last updated 2024-08-06 06:50:02
Assigner mitre
CVSS score not scored
State PUBLISHED

Description

The sanitize_string function in ZenPhoto before 1.4.9 utilized the html_entity_decode function after input sanitation, which might allow remote attackers to perform a cross-site scripting (XSS) via a crafted string.