Gallery · Gallery 3 · CVE-2012-4342
**Name of the Vulnerable Software and Affected Versions**
Gallery 3 versions prior to 3.0.4
**Description**
The issue allows remote attackers to inject arbitrary web script or HTML via unspecified vectors, which can lead to cross-site scripting (XSS) attacks.
**Recommendations**
For Gallery 3 versions prior to 3.0.4, update to version 3.0.4 or later to resolve the issue.