Impact
The vulnerability resides in the db_input.php file of the Hidden Album Update Endpoint in Coppermine Photo Gallery versions up to 1.6.28. The flaw allows an attacker to inject malicious scripts into album descriptions, resulting in a cross‑site scripting (XSS) condition, an instance of CWE‑79. The flaw is also related to CWE‑94, reflecting improper control of code execution. With remote exploitation, an attacker can execute arbitrary JavaScript in the context of any user who views the affected album, potentially stealing session cookies or defacing content.
Affected Systems
The affected product is Coppermine Photo Gallery, versions prior to 1.6.29. The advisory indicates that upgrading to version 1.6.29 or newer eliminates the flaw. No other vendors are listed, and the CVE does not mention other affected components.
Risk and Exploitability
The CVSS score is 5.1, reflecting a moderate impact. The EPSS score is not available, and the vulnerability is not listed in the CISA KEV catalog, suggesting it has not yet been widely exploited in the wild. Nevertheless, the public exploit is known, and the remote attack surface means that any user who can access the hidden album update endpoint could trigger the XSS and compromise client sessions.
OpenCVE Enrichment