Unrated severityNVD Advisory· Published May 31, 2015· Updated Jun 17, 2026
CVE-2015-2948
CVE-2015-2948
Description
Cross-site scripting (XSS) vulnerability in the image processor in Zenphoto before 1.4.8 allows remote attackers to inject arbitrary web script or HTML via unspecified vectors.
AI Insight
LLM-synthesized narrative grounded in this CVE's description and references.
Affected products
2Patches
Vulnerability mechanics
References
4- jvn.jp/en/jp/JVN68452022/index.htmlnvdVendor Advisory
- jvndb.jvn.jp/jvndb/JVNDB-2015-000070nvdVendor Advisory
- www.zenphoto.org/news/zenphoto-1.4.8nvdVendor Advisory
- www.securityfocus.com/bid/74895nvd
News mentions
0No linked articles in our index yet.