What the vulnerability does
01Description
Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting') vulnerability in 10Web Slider by 10Web allows Reflected XSS.This issue affects Slider by 10Web: from n/a through 1.2.54.
CVSS base score
CVSS vector
CVSS:3.1/AV:N/AC:L/PR:N/UI:R/S:C/C:L/I:L/A:L
What the vulnerability does
Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting') vulnerability in 10Web Slider by 10Web allows Reflected XSS.This issue affects Slider by 10Web: from n/a through 1.2.54.
Explanation of Vulnerability in Simple Terms
Slider by 10Web versions up to 1.2.54 contain a stored cross-site scripting (XSS) vulnerability. An attacker can inject malicious JavaScript into slider content that executes in the browsers of site visitors. The vulnerability affects the scope beyond the vulnerable component, potentially compromising user sessions and data. Site administrators should update to a version newer than 1.2.54.
What an attacker can do
Inject malicious JavaScript that runs in visitors' browsers when they view affected sliders.
Potential impact on your site
Attackers can steal visitor session cookies, redirect users, or deface slider content without your knowledge.
Conditions required to exploit
No authentication required. A visitor must view a page containing an affected slider.
Key dates
External resources
Related vulnerabilities