vendor:
Community Gallery
by:
Pham Kien Cuong & ITAS Team
8.8
CVSS
HIGH
Stored Cross-Site Scripting
79
CWE
Product Name: Community Gallery
Affected Version From: Community Gallery 2.0 before 12/10/2014
Affected Version To: Community Gallery 2.0 before 12/26/2014
Patch Exists: YES
Related CWE: CVE-2015-2275
CPE: a:woltlab:community_gallery:2.0
Metasploit:
N/A
Tags: N/A
CVSS Metrics: N/A
Nuclei References:
N/A
Nuclei Metadata: N/A
Platforms Tested: None
2015
Community Gallery – Stored Cross-Site Scripting vulnerability
Community Gallery 2.0 before 12/10/2014 is vulnerable to Stored Cross-Site Scripting (XSS) vulnerability. An attacker can inject malicious JavaScript code into the description field of an image, which will be executed when the image is viewed by an authenticated user. This can be exploited to execute arbitrary HTML and script code in a user's browser session in context of an affected site.
Mitigation:
Upgrade to Community Gallery 2.0 after 12/26/2014