CVE-2023-53916
EUVD-2023-6021417.12.2025, 23:15
Zenphoto 1.6 contains a stored cross-site scripting vulnerability in the user postal code field accessible through the admin-users.php interface. When administrators view user information imported as HTML, malicious JavaScript payloads injected into the postal code field execute in their browser context.
Affected Products (NVD)
| Vendor | Product | Version |
|---|---|---|
| zenphoto | zenphoto | 1.6 |
𝑥
= Vulnerable software versions