Cross Site Scripting (XSS) Vulnerability in Imagely NextGEN Gallery 2.2.30 and Earlier

Cross Site Scripting (XSS) Vulnerability in Imagely NextGEN Gallery 2.2.30 and Earlier

CVE-2018-1000172 · LOW Severity

AV:N/AC:M/AU:S/C:N/I:P/A:N

Imagely NextGEN Gallery version 2.2.30 and earlier contains a Cross Site Scripting (XSS) vulnerability in Image Alt & Title Text. This attack appears to be exploitable via a victim viewing the image in the administrator page. This vulnerability appears to have been fixed in 2.2.45.

Learn more about our Web Application Penetration Testing UK.