vendor:
Simple Image Gallery Extended
by:
Alwin Peppels
6.1
CVSS
MEDIUM
Cross-site Scripting
79
CWE
Product Name: Simple Image Gallery Extended
Affected Version From: 3.2.0
Affected Version To: 3.2.3
Patch Exists: YES
Related CWE: CVE-2017-16356
CPE: a:kubik-rubik:simple_image_gallery_extended
Metasploit:
N/A
Other Scripts:
N/A
Platforms Tested: None
2018
Joomla! Component SIGE version <= 3.2.3 Cross-site Scripting
Kubik-Rubik Simple Image Gallery Extended (SIGE) contains an XSS in the 'print.php' file. Insufficient sanitization of the 'caption' URL parameter allows injection of Javascript into the page. In versions <= 3.2.0 the 'name' and 'img' parameters are vulnerable as well.
Mitigation:
Update to version 3.3.0