What the vulnerability does
01Description
Auth. (admin+) Stored Cross-Site Scripting (XSS) vulnerability in Tauhidul Alam Simple Portfolio Gallery plugin <= 0.1 versions.
CVSS base score
CVSS vector
CVSS:3.1/AV:N/AC:L/PR:H/UI:R/S:C/C:L/I:L/A:L
What the vulnerability does
Auth. (admin+) Stored Cross-Site Scripting (XSS) vulnerability in Tauhidul Alam Simple Portfolio Gallery plugin <= 0.1 versions.
Explanation of Vulnerability in Simple Terms
Simple Portfolio Gallery version 0.1 and earlier contains a cross-site scripting (XSS) vulnerability. An authenticated administrator can inject malicious scripts through the plugin interface. When another user visits an affected page, the script executes in their browser, potentially compromising their session or stealing data. A patch version is not currently available.
What an attacker can do
Inject malicious JavaScript that runs in other users' browsers when they view the gallery.
Potential impact on your site
An admin account compromise could allow an attacker to inject malware visible to all site visitors.
Conditions required to exploit
Attacker must have administrator privileges and the victim must visit a page containing the injected content.
Key dates
External resources
Related vulnerabilities