PT-2026-79527 · Joomla · Joomgallery
CVSS v4.0
8.6
High
| Vector | AV:N/AC:L/AT:N/PR:H/UI:N/VC:H/VI:H/VA:H/SC:N/SI:N/SA:N |
Name of the Vulnerable Software and Affected Versions
JoomGallery versions prior to 4.4.0
Description
An authenticated user with privileged access can store a Cross-Site Scripting (XSS) payload within an image. This allows the execution of arbitrary JavaScript in the browser of every visitor who views the affected image.
Recommendations
Update JoomGallery to version 4.4.0 or later.
Fix
XSS
Found an issue in the description? Have something to add? Feel free to write us 👾
Weakness Enumeration
Related Identifiers
Affected Products
Joomgallery