Impact
A stored cross‑site scripting flaw exists in the profile.php component of Coppermine Photo Gallery. User supplied input in the Biography field is rendered without proper sanitization, allowing an attacker to inject arbitrary JavaScript that runs in the browsers of anyone who views the affected profile. Such scripts can read cookies, steal session tokens, or perform unauthorized actions on behalf of the user, leading to privacy or credential compromise. The weakness is an input‑validation error classified as CWE‑79.
Affected Systems
The vulnerability affects all instances of Coppermine Photo Gallery versions up to and including 1.6.28. Upgrading to version 1.6.29 or later removes the flaw.
Risk and Exploitability
With a CVSS score of 5.1 the risk is moderate. The EPSS score is unavailable and it is not listed in CISA's KEV catalog. Based on the description, it is inferred that the attack can be initiated remotely by submitting crafted data to the Biography field, making the flaw potentially exploitable in environments where user input is not strictly controlled. Public disclosures and proofs of concept have been released, indicating that exploitation is feasible with moderate effort.
OpenCVE Enrichment