What the vulnerability does
01Description
Improper Neutralization of Input During Web Page Generation (XSS or 'Cross-site Scripting') vulnerability in ThemeGrill Himalayas allows Stored XSS.This issue affects Himalayas: from n/a through 1.3.2.
CVSS base score
CVSS vector
CVSS:3.1/AV:N/AC:L/PR:H/UI:R/S:C/C:L/I:L/A:L
What the vulnerability does
Improper Neutralization of Input During Web Page Generation (XSS or 'Cross-site Scripting') vulnerability in ThemeGrill Himalayas allows Stored XSS.This issue affects Himalayas: from n/a through 1.3.2.
Explanation of Vulnerability in Simple Terms
Himalayas through version 1.3.2 contains a stored cross-site scripting (XSS) vulnerability that allows authenticated administrators to inject malicious scripts. An attacker with admin privileges can craft input that executes JavaScript in other users' browsers when they view affected pages. The vulnerability requires user interaction and affects site integrity and confidentiality.
What an attacker can do
Inject malicious JavaScript that runs in other users' browsers when they view the site.
Potential impact on your site
Administrators could be tricked into visiting malicious pages, potentially compromising their accounts or exposing sensitive data.
Conditions required to exploit
Attacker must have administrator privileges and the victim must visit a page containing the injected content.
Key dates
External resources
Related vulnerabilities