CVE-2018-1000172: XSS
Imagely NextGEN Gallery version 2.2.30 and earlier contains a Cross Site Scripting (XSS) vulnerability in Image Alt & Title Text. This attack appears to be exploitable via a victim viewing the image in the administrator page. This vulnerability appears to have been fixed in 2.2.45.
Affected Software
Event History
Frequently Asked Questions
What is CVE-2018-1000172?
CVE-2018-1000172 is a Cross Site Scripting (XSS) vulnerability found in Imagely NextGEN Gallery version 2.2.30 and earlier.
How can the CVE-2018-1000172 vulnerability be exploited?
The vulnerability can be exploited by viewing the image in the administrator page.
What is the severity of CVE-2018-1000172?
The severity of CVE-2018-1000172 is medium with a severity value of 4.8.
Has CVE-2018-1000172 been fixed?
Yes, the vulnerability has been fixed in version 2.2.45 of Imagely NextGEN Gallery.
How can I get more information about CVE-2018-1000172?
You can find more information about CVE-2018-1000172 at the following references: [FortiGuard](https://fortiguard.com/zeroday/FG-VD-17-215) and [WordPress](https://wordpress.org/plugins/nextgen-gallery/#developers).