vendor:
4Images Gallery
by:
Piyush Patil
4.8
CVSS
MEDIUM
Reflected XSS
79
CWE
Product Name: 4Images Gallery
Affected Version From: 4Images Gallery 1.8
Affected Version To: 4Images Gallery 1.8
Patch Exists: YES
Related CWE: CVE-2021-27308
CPE: 4images
Metasploit:
N/A
Other Scripts:
https://www.infosecmatter.com/nessus-plugin-library/?id=27308, https://www.infosecmatter.com/nessus-plugin-library/?id=24948, https://www.infosecmatter.com/nessus-plugin-library/?id=24943, https://www.infosecmatter.com/nessus-plugin-library/?id=24935, https://www.infosecmatter.com/nessus-plugin-library/?id=24919, https://www.infosecmatter.com/nessus-plugin-library/?id=67458, https://www.infosecmatter.com/nessus-plugin-library/?id=28046, https://www.infosecmatter.com/nessus-plugin-library/?id=26153
Platforms Tested: Windows 10 and Kali
2021
4Images 1.8 – ‘redirect’ Reflected XSS
A cross-site scripting (XSS) vulnerability in the admin login panel in 4images version 1.8 allows remote attackers to inject JavaScript via the 'redirect' parameter.
Mitigation:
Input validation and output encoding should be used to prevent XSS attacks.