CVE-2024-10102

The Photo Gallery, Images, Slider in Rbs Image Gallery WordPress plugin before 3.2.22 does not sanitise and escape some of its Gallery settings, which could allow high privilege users such as contributor to perform Stored Cross-Site Scripting attacks
Configurations

Configuration 1 (hide)

cpe:2.3:a:robosoft:robo_gallery:*:*:*:*:*:wordpress:*:*

History

14 May 2025, 13:46

Type Values Removed Values Added
References () https://wpscan.com/vulnerability/3b34d1ec-5370-40a8-964e-663f4f9f42f8/ - () https://wpscan.com/vulnerability/3b34d1ec-5370-40a8-964e-663f4f9f42f8/ - Exploit, Third Party Advisory
CWE CWE-79
First Time Robosoft robo Gallery
Robosoft
CPE cpe:2.3:a:robosoft:robo_gallery:*:*:*:*:*:wordpress:*:*

07 Jan 2025, 17:15

Type Values Removed Values Added
References () https://wpscan.com/vulnerability/3b34d1ec-5370-40a8-964e-663f4f9f42f8/ - () https://wpscan.com/vulnerability/3b34d1ec-5370-40a8-964e-663f4f9f42f8/ -
CVSS v2 : unknown
v3 : unknown
v2 : unknown
v3 : 2.7
Summary
  • (es) Photo Gallery, Images, Slider en Rbs Image Gallery WordPress del complemento de WordPress anterior a la versión 3.2.22 no desinfecta ni evita algunas de las configuraciones de la galería, lo que podría permitir que usuarios con privilegios elevados, como los colaboradores, realicen ataques de cross site scripting almacenado

07 Jan 2025, 06:15

Type Values Removed Values Added
New CVE

Information

Published : 2025-01-07 06:15

Updated : 2025-05-14 13:46


NVD link : CVE-2024-10102

Mitre link : CVE-2024-10102

CVE.ORG link : CVE-2024-10102


JSON object : View

Products Affected

robosoft

  • robo_gallery
CWE
CWE-79

Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting')