PT-2025-38816 · Unknown · Ghozylab Gallery Lightbox
Prissy
·
Published
2025-09-22
·
Updated
2025-09-22
·
CVE-2025-57966
CVSS v3.1
6.5
Medium
| Vector | AV:N/AC:L/PR:L/UI:R/S:C/C:L/I:L/A:L |
Name of the Vulnerable Software and Affected Versions
GhozyLab Gallery Lightbox versions through 1.0.0.41
Description
The software contains a flaw due to improper input handling during web page creation, leading to a Cross-site Scripting (XSS) issue. Specifically, the vulnerability allows for Stored XSS attacks. The issue involves the injection of malicious scripts into web pages, potentially compromising user data and system security. The affected API endpoints and vulnerable parameters are not specified.
Recommendations
Update GhozyLab Gallery Lightbox to a version later than 1.0.0.41.
Fix
XSS
Found an issue in the description? Have something to add? Feel free to write us 👾
Weakness Enumeration
Related Identifiers
Affected Products
Ghozylab Gallery Lightbox