PT-2025-4963 · Unknown · Rio Photo Gallery

João Pedro S Alcântara

·

Published

2025-01-22

·

Updated

2025-01-22

·

CVE-2025-23597

CVSS v3.1

7.1

High

VectorAV:N/AC:L/PR:N/UI:R/S:C/C:L/I:L/A:L
Name of the Vulnerable Software and Affected Versions Rio Photo Gallery versions 0.1 and earlier
Description The issue is related to improper neutralization of input during web page generation, which allows reflected Cross-site Scripting (XSS). This means an attacker can inject malicious scripts into the website, potentially affecting users who visit the compromised page.
Recommendations For Rio Photo Gallery versions 0.1 and earlier, as a temporary workaround, consider disabling any functionality that allows user input to be reflected in the web page until a patch is available. Restrict access to any modules or functions that generate web pages based on user input to minimize the risk of exploitation. At the moment, there is no information about a newer version that contains a fix for this vulnerability.

XSS

Found an issue in the description? Have something to add? Feel free to write us 👾

Weakness Enumeration

Related Identifiers

CVE-2025-23597

Affected Products

Rio Photo Gallery