What the vulnerability does
01Description
Auth. (admin+) Stored Cross-Site Scripting (XSS) vulnerability in Video Gallery by Total-Soft Video Gallery plugin <= 1.7.6 versions.
CVSS base score
CVSS vector
CVSS:3.1/AV:N/AC:L/PR:H/UI:R/S:C/C:L/I:L/A:L
What the vulnerability does
Auth. (admin+) Stored Cross-Site Scripting (XSS) vulnerability in Video Gallery by Total-Soft Video Gallery plugin <= 1.7.6 versions.
Explanation of Vulnerability in Simple Terms
Video Gallery through version 1.7.6 contains a cross-site scripting (XSS) vulnerability that allows an authenticated administrator to inject malicious scripts. The vulnerability requires user interaction—typically clicking a malicious link—and can affect other users viewing the site. An attacker with high-level privileges can inject code that executes in victims' browsers, potentially stealing session data or performing actions on their behalf.
What an attacker can do
Inject malicious JavaScript that runs in other users' browsers when they view affected pages.
Potential impact on your site
An admin account compromise could allow session hijacking or unauthorized actions against site visitors and other administrators.
Conditions required to exploit
Attacker must have administrator-level access and the victim must click a crafted link or visit a page containing the payload.
Key dates
External resources
Related vulnerabilities