What the vulnerability does
01Description
Joomla Extension - joomgalleryfriends.net - Stored XSS in JoomGallery < 4.4.0 - An authenticated, privileged can store an XSS payload in any image causing JS execution in every visitor's browser.
CVSS base score
CVSS vector
CVSS:4.0/AV:N/AC:L/AT:N/PR:H/UI:N/VC:H/VI:H/VA:H/SC:N/SI:N/SA:N
What the vulnerability does
Joomla Extension - joomgalleryfriends.net - Stored XSS in JoomGallery < 4.4.0 - An authenticated, privileged can store an XSS payload in any image causing JS execution in every visitor's browser.
Explanation of Vulnerability in Simple Terms
JoomGallery extension for Joomla versions 4.0.0 through 4.3.0 contains a cross-site scripting (XSS) vulnerability that allows high-privileged users to inject malicious scripts. An attacker with administrative or elevated permissions can craft input that executes JavaScript in the browsers of other site visitors, potentially compromising user sessions or stealing sensitive data.
What an attacker can do
Inject and execute malicious JavaScript in other users' browsers via the JoomGallery interface.
Potential impact on your site
Compromised admin accounts can inject scripts affecting all site visitors, risking session hijacking and data theft.
Conditions required to exploit
Attacker must have high-level privileges (admin or equivalent role) on the Joomla site.
Key dates
External resources
Related vulnerabilities