Stored cross-site scripting vulnerability in Zenphoto versions prior to 1.6 allows remote a remote authenticated attacker with an administrative privilege to inject an arbitrary script.
[
{
"vendor": "Zenphoto",
"product": "Zenphoto",
"versions": [
{
"version": "versions prior to 1.6",
"status": "affected"
}
]
}
]