CVE-2024-10102

The Photo Gallery, Images, Slider in Rbs Image Gallery WordPress plugin before 3.2.22 does not sanitise and escape some of its Gallery settings, which could allow high privilege users such as contributor to perform Stored Cross-Site Scripting attacks
Configurations

Configuration 1 (hide)

cpe:2.3:a:robosoft:robo_gallery:*:*:*:*:*:wordpress:*:*

History

14 May 2025, 13:46

Type Values Removed Values Added
CWE CWE-79
References () https://wpscan.com/vulnerability/3b34d1ec-5370-40a8-964e-663f4f9f42f8/ - () https://wpscan.com/vulnerability/3b34d1ec-5370-40a8-964e-663f4f9f42f8/ - Exploit, Third Party Advisory
CPE cpe:2.3:a:robosoft:robo_gallery:*:*:*:*:*:wordpress:*:*
First Time Robosoft robo Gallery
Robosoft

07 Jan 2025, 17:15

Type Values Removed Values Added
References () https://wpscan.com/vulnerability/3b34d1ec-5370-40a8-964e-663f4f9f42f8/ - () https://wpscan.com/vulnerability/3b34d1ec-5370-40a8-964e-663f4f9f42f8/ -
CVSS v2 : unknown
v3 : unknown
v2 : unknown
v3 : 2.7
Summary
  • (es) Photo Gallery, Images, Slider en Rbs Image Gallery WordPress del complemento de WordPress anterior a la versión 3.2.22 no desinfecta ni evita algunas de las configuraciones de la galería, lo que podría permitir que usuarios con privilegios elevados, como los colaboradores, realicen ataques de cross site scripting almacenado

07 Jan 2025, 06:15

Type Values Removed Values Added
New CVE

Information

Published : 2025-01-07 06:15

Updated : 2025-05-14 13:46


NVD link : CVE-2024-10102

Mitre link : CVE-2024-10102

CVE.ORG link : CVE-2024-10102


JSON object : View

Products Affected

robosoft

  • robo_gallery
CWE
CWE-79

Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting')