5.4
CVE-2024-29810
- EPSS 0.41%
- Veröffentlicht 26.03.2024 16:15:12
- Zuletzt bearbeitet 09.04.2025 15:41:36
- Quelle info@appcheck-ng.com
- CVE-Watchlists
- Unerledigt
WordPress Photo Gallery Plugin <= 1.8.21 Reflected Cross Site Scripting in editimage_bwg thumb_url
Photo Gallery by 10Web – Mobile-Friendly Image Gallery <= 1.8.21 - Reflected Cross-Site Scripting via 'thumb_url'
The thumb_url parameter of the AJAX call to the editimage_bwg action of admin-ajax.php is vulnerable to reflected Cross Site Scripting. The value of the thumb_url parameter is embedded within an existing JavaScript within the response allowing arbitrary JavaScript to be inserted and executed. The attacker must target a an authenticated user with permissions to access this component to exploit this issue.
Mögliche Gegenmaßnahme
Photo Gallery by 10Web – Mobile-Friendly Image Gallery: Update to version 1.8.22, or a newer patched version
Daten sind bereitgestellt durch National Vulnerability Database (NVD)
10web ≫ Photo Gallery SwPlatformwordpress Version < 1.8.22
VulnDex Vulnerability Enrichment
Weitere Schwachstelleninformationen
SystemWordPress Plugin
≫
Produkt
Photo Gallery by 10Web – Mobile-Friendly Image Gallery
Version
*-1.8.21
| Typ | Quelle | Score | Percentile |
|---|---|---|---|
| EPSS | FIRST.org | 0.41% | 0.327 |
| Quelle | Base Score | Exploit Score | Impact Score | Vector String |
|---|---|---|---|---|
| nvd@nist.gov | 5.4 | 2.3 | 2.7 |
CVSS:3.1/AV:N/AC:L/PR:L/UI:R/S:C/C:L/I:L/A:N
|
| info@appcheck-ng.com | 5.4 | 2.3 | 2.7 |
CVSS:3.1/AV:N/AC:L/PR:L/UI:R/S:C/C:L/I:L/A:N
|
CWE-79 Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting')
The product does not neutralize or incorrectly neutralizes user-controllable input before it is placed in output that is used as a web page that is served to other users.
https://wordpress.org/plugins/photo-gallery/#developers
https://appcheck-ng.com/xss-vulnerabilities-discovered-10web-photogallery-wordpress-plugin/
https://www.wordfence.com/threat-intel/vulnerabilities/id/d254e43f-8a8b-4309-91f3-c60710c13647