CVE-2024-29809 MEDIUM

CVE-2024-29809: WordPress Photo Gallery Plugin <= 1.8.21 Reflected Cross Site Scripting in editimage_bwg image_url

Vendor 10Web
Product PhotoGallery
Weakness CWE-79 · XSS
Published March 26, 2024
Last update August 2, 2024

CVSS base score

5.4/10
Attack vector Network
Attack complexity Low
Privileges required Low
User interaction Required
Confidentiality Low
Integrity Low

CVSS vector

CVSS:3.1/AV:N/AC:L/PR:L/UI:R/S:C/C:L/I:L/A:N

What the vulnerability does

01Description

The image_url parameter of the AJAX call to the editimage_bwg action of admin-ajax.php is vulnerable to reflected Cross Site Scripting. The value of the image_url parameter is embedded within an existing JavaScript within the response allowing arbitrary JavaScript to be inserted and executed. The attacker must target a an authenticated user with permissions to access this component to exploit this issue.

Explanation of Vulnerability in Simple Terms

02Summary

PhotoGallery versions 1.0.1 through 1.8.21 contain a stored cross-site scripting (XSS) vulnerability. An authenticated user with low privileges can inject malicious scripts that execute in the browsers of other users viewing the gallery. The vulnerability requires user interaction—victims must visit a page containing the injected content. The impact is limited to session hijacking or credential theft within the site.

What an attacker can do

03Attacker Capabilities

Inject malicious scripts that run in other users' browsers when they view the gallery.

Potential impact on your site

04Site Impact

Users' sessions or credentials could be stolen if they view galleries containing injected scripts.

Conditions required to exploit

05Prerequisites

Attacker must have a low-privilege account on the site; victim must visit a page with the injected content.

Key dates

06Disclosure timeline

March 26, 2024 CVE published
August 2, 2024 Record updated

Related vulnerabilities

08Related CVE