Lucene search

K
wpexploitLucyWPEX-ID:1BFFBBEF-7876-43A6-9CB0-6E09BB4FF2B0
HistoryJun 06, 2022 - 12:00 a.m.

NextCellent Gallery <= 1.9.35 - Admin+ Stored XSS

2022-06-0600:00:00
lucy
108
nextcellent gallery
stored xss
admin+
edit gallery
payload
alt & title text
stored exploit

EPSS

0.001

Percentile

24.8%

The plugin does not sanitise and escape some of its image settings, which could allow high privilege users such as admin to perform Stored Cross-Site Scripting attacks when the unfiltered_html capability is disallowed (for example in multisite setup)

Create/edit a gallery with at least one image, put the following payload in the "Alt & Title Text" field: State of Mind"autofocus onfocus=alert(/XSS/)//

Save the changes (via the button next to the Apply button). The XSS will be triggered when editing the Gallery again

EPSS

0.001

Percentile

24.8%

Related for WPEX-ID:1BFFBBEF-7876-43A6-9CB0-6E09BB4FF2B0