Input passed to the 'css' parameter from '/docs/showdoc.php' of Coppermine's Photo Gallery is not sanitized before it is returned to the user. This can be exploited to execute arbitrary HTML and script code in a user's browser session in context of an affected site.
Vulnerable Systems:
* Coppermine Photo Gallery version 1.4.21and earlier
Immune Systems:
* Coppermine Photo Gallery version 1.4.22 and later
Vendor Response:
Users running versions prior to 1.4.22 should update immediately by downloading the latest version from the download page and following the upgrade steps in the documentation.
For those who want to apply the vulnerability fix manually to their Coppermine installation, open docs/showdoc.php and replace:
Code: