PT-2022-25413 · 10Web · The Photo Gallery
Kazet1234
+1
·
Published
2022-12-19
·
Updated
2022-12-22
·
CVE-2022-4058
CVSS v3.1
5.4
Medium
| Vector | AV:N/AC:L/PR:L/UI:R/S:C/C:L/I:L/A:N |
Name of the Vulnerable Software and Affected Versions
The Photo Gallery by 10Web WordPress plugin versions prior to 1.8.3
Description
The issue arises from the plugin's failure to validate and escape certain parameters before outputting them in JS code on another page. This could lead to a Stored XSS issue when an attacker tricks a logged-in admin into opening a malicious URL or page.
Recommendations
For versions prior to 1.8.3, update to version 1.8.3 or later to resolve the issue. As a temporary workaround, consider restricting access to the plugin's functionality for logged-in admins until the update is applied.
Exploit
Fix
Found an issue in the description? Have something to add? Feel free to write us 👾
Related Identifiers
Affected Products
The Photo Gallery