Web / CMS

Cross-Site Scripting (XSS)

XSS in admiror gallery 5.2.0

xss in admiror gallery 5.2.0 The Application does not sanitize or escape AG_responseType parameter, making it vulnerable to reflected cross-site scripting attacks (XSS) when a victim opens the…

6.1
/ 10
Medium
CVSS v3.1
ADVISORY ID
PS86
PUBLISHED
2023-08-16
CVE IDs
CVE-2023-38045
VENDORS
Admiror Design Studio
PUBLIC EXPLOIT
None indexed
CWE
CWE-79
PRODUCT
Admiror Gallery (Joomla)
CVSS VECTOR
CVSS:3.1/AV:N/AC:L/PR:N/UI:R/S:C/C:L/I:L/A:N
Abstract blurred background with dark tones and smooth gradient waves of blue, purple, and orange hues.
Summary

Overview

xss in admiror gallery 5.2.0

The Application does not sanitize or escape AG_responseType parameter, making it vulnerable to reflected cross-site scripting attacks (XSS) when a victim opens the malicious url sent by an attacker.

Vulnerability details

Vulnerability details

CVE-2023-38045
CWE-79
Medium | 6.1

xss in admiror gallery 5.2.0 The Application does not sanitize or escape AG_responseType parameter, making it vulnerable to reflected cross-site scripting attacks (XSS) when a victim opens the malicious url sent by an attacker.

Auth:
None (remote, user interaction required)
Impact:
Limited data disclosure, limited data tampering; impact extends beyond the vulnerable component
DISCLOSURE

Disclosure timeline

2023-08-07 Made Public On

2023-07-06 Reported On

Fixed On: Not Fixed

Credits

Vishal and Siva