PT-2024-27556 · Ays · Photo Gallery

Ibnu Ubaeydillah

·

Published

2024-07-09

·

Updated

2024-08-29

·

CVE-2024-37442

CVSS v3.1

5.5

Medium

VectorAV:N/AC:L/PR:H/UI:N/S:U/C:N/I:H/A:L
Name of the Vulnerable Software and Affected Versions Photo Gallery by Ays versions prior to 5.7.1
Description The issue is related to an Improper Neutralization of Special Elements in Output Used by a Downstream Component, also known as an 'Injection' vulnerability, in the Photo Gallery Team Photo Gallery by Ays. This allows for Code Injection.
Recommendations For versions prior to 5.7.1, update to version 5.7.1 or later to resolve the issue.

Fix

Special Elements Injection

Weakness Enumeration

Related Identifiers

CVE-2024-37442

Affected Products

Photo Gallery