PT-2018-6279 · Kubik Rubik · Kubik-Rubik Sige
Alwin Peppels
·
Published
2018-02-20
·
Updated
2018-03-05
·
CVE-2017-16356
CVSS v3.1
6.1
Medium
| Vector | AV:N/AC:L/PR:N/UI:R/S:C/C:L/I:L/A:N |
Name of the Vulnerable Software and Affected Versions:
Kubik-Rubik SIGE (aka Simple Image Gallery Extended) versions prior to 3.3.0
Description:
The issue allows attackers to execute JavaScript in a victim's browser. This is achieved by having the victim visit a crafted link, specifically a 'plugins/content/sige/plugin sige/print.php' link, with malicious
img, name, or caption parameters.Recommendations:
For versions prior to 3.3.0, update to version 3.3.0 or later to resolve the issue. As a temporary workaround, consider restricting access to the 'plugins/content/sige/plugin sige/print.php' endpoint or avoiding the use of the
img, name, and caption parameters in this context until the update is applied.Exploit
Fix
XSS
Found an issue in the description? Have something to add? Feel free to write us 👾
Weakness Enumeration
Related Identifiers
Affected Products
Kubik-Rubik Sige