Lucene search

K
wpexploitKaushalendra DubeyWPEX-ID:D5CE4B8A-9AA5-4DF8-B521-C2105990A87E
HistoryApr 25, 2022 - 12:00 a.m.

Gmedia Photo Gallery < 1.20.0 - Admin+ Stored Cross-Site Scripting

2022-04-2500:00:00
Kaushalendra Dubey
84

0.001 Low

EPSS

Percentile

24.8%

The plugin does not sanitise and escape the Album’s name before outputting it in pages/posts with a media embed, which could allow high privilege users such as admin to perform Cross-Site Scripting attacks even when the unfiltered-html capability is disallowed

https://youtu.be/kTMg65teTvU

Create an Album with the following payload as Name: test"><img src onerror=alert(/XSS/)>
Add a media via the "Add/Import files" menu and select the album created above

The XSS will be triggered when viewing the media post

0.001 Low

EPSS

Percentile

24.8%

Related for WPEX-ID:D5CE4B8A-9AA5-4DF8-B521-C2105990A87E