Vulnerability Explanation: Piwigo Version 12.3.0 has XSS vulnerabilities that allow attackers to store XSS via tag input. Affected Component: http://[IP]/admin.php?page=tags Payload: <image src/onerror=console.log("test_xss_at_Tags")> Tested on: Piwigo Version 12.3.0 https://piwigo.org/get-piwigoa Brave Version 1.44.101 Chromium: 106.0.5249.65 (Official Build) (64-bit) Steps to attack: 1. First, we log in with an admin credential to the target application.