Description
ecard.php in Coppermine Photo Gallery (CPG) 1.5.46 has XSS via the sender_name, recipient_email, greetings, or recipient_name parameter.
Remediation
References
Related Vulnerabilities
PHP Permissions, Privileges, and Access Controls Vulnerability (CVE-2012-3365)
Django Cross-Site Request Forgery (CSRF) Vulnerability (CVE-2011-4140)
WordPress Plugin Anti-Malware Security and Brute-Force Firewall Cross-Site Scripting (4.17.29)
Caddy Web Server Improper Authentication Vulnerability (CVE-2018-21246)