What the vulnerability does
01Description
Auth. (admin+) Stored Cross-Site Scripting (XSS) vulnerability in Gopi Ramasamy Image vertical reel scroll slideshow plugin <= 9.0 versions.
CVSS base score
CVSS vector
CVSS:3.1/AV:N/AC:L/PR:H/UI:R/S:C/C:L/I:L/A:L
What the vulnerability does
Auth. (admin+) Stored Cross-Site Scripting (XSS) vulnerability in Gopi Ramasamy Image vertical reel scroll slideshow plugin <= 9.0 versions.
Explanation of Vulnerability in Simple Terms
Image vertical reel scroll slideshow through version 9.0 contains a stored cross-site scripting (XSS) vulnerability. An authenticated administrator can inject malicious scripts into the slideshow configuration. When other users view the affected page, the injected code executes in their browser, potentially compromising their session or stealing data.
What an attacker can do
Inject and execute malicious JavaScript in the browsers of site visitors.
Potential impact on your site
Administrators can inject malicious code affecting all site visitors; compromised admin accounts pose a site-wide risk.
Conditions required to exploit
Attacker must have administrator privileges and a victim must view the affected slideshow page.
Key dates
External resources
Related vulnerabilities