CVE-2024-10102

T

he Photo Gallery, Images, Slider in Rbs Image Gallery WordPress plugin before 3.2.22 does not sanitise and escape some of its Gallery settings, which could allow high privilege users such as contributor to perform Stored Cross-Site Scripting attacks

Configurations

Configuration 1 (hide)

cpe:2.3:a:robosoft:robo_gallery:*:*:*:*:*:wordpress:*:*

History

14 May 2025, 13:46

Type Values Removed Values Added
CPE cpe:2.3:a:robosoft:robo_gallery:*:*:*:*:*:wordpress:*:*
First Time Robosoft robo Gallery
Robosoft
References () https://wpscan.com/vulnerability/3b34d1ec-5370-40a8-964e-663f4f9f42f8/ - () https://wpscan.com/vulnerability/3b34d1ec-5370-40a8-964e-663f4f9f42f8/ - Exploit, Third Party Advisory
CWE CWE-79

07 Jan 2025, 17:15

Type Values Removed Values Added
Summary
  • (es) Photo Gallery, Images, Slider en Rbs Image Gallery WordPress del complemento de WordPress anterior a la versión 3.2.22 no desinfecta ni evita algunas de las configuraciones de la galería, lo que podría permitir que usuarios con privilegios elevados, como los colaboradores, realicen ataques de cross site scripting almacenado
CVSS v2 : unknown
v3 : unknown
v2 : unknown
v3 : 2.7
References () https://wpscan.com/vulnerability/3b34d1ec-5370-40a8-964e-663f4f9f42f8/ - () https://wpscan.com/vulnerability/3b34d1ec-5370-40a8-964e-663f4f9f42f8/ -

07 Jan 2025, 06:15

Type Values Removed Values Added
New CVE

Information

Published : 2025-01-07 06:15

Updated : 2025-05-14 13:46


NVD link : CVE-2024-10102

Mitre link : CVE-2024-10102

CVE.ORG link : CVE-2024-10102


JSON object : View

Products Affected
CWE
CWE-79

Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting')