CVE-2024-29921: WordPress Photo Gallery by Supsystic plugin <= 1.15.16 - Cross Site Scripting (XSS) vulnerability
Published Mar 27, 2024
·Updated
Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting') vulnerability in supsystic Photo Gallery by Supsystic gallery-by-supsystic.This issue affects Photo Gallery by Supsystic: from n/a through <= 1.15.16.
Affected Software
3 affected components
Supsystic Photo Gallery Wordpress<1.15.17
Supsystic Photo Gallery<=1.15.16
Supsystic WordPress Photo Gallery<=1.15.16
Remediation
Information
Update to 1.15.17 or a higher version.
Event History
Mar 27, 2024
CVE Published
via MITRE·07:14 AM
Data Sourced
via MITRE·07:14 AM
DescriptionSeverityWeakness
Data Sourced
via NVD·08:15 AM
DescriptionSeverityWeaknessAffected Software
Frequently Asked Questions
1
What is the severity of CVE-2024-29921?
CVE-2024-29921 is classified as a medium severity vulnerability due to its potential for exploitation via stored cross-site scripting.
2
How do I fix CVE-2024-29921?
To fix CVE-2024-29921, update the Photo Gallery by Supsystic to version 1.15.17 or later.
3
Which versions of the Supsystic Photo Gallery are affected by CVE-2024-29921?
CVE-2024-29921 affects all versions of the Supsystic Photo Gallery up to and including 1.15.16.
4
What attack vector does CVE-2024-29921 utilize?
CVE-2024-29921 utilizes stored cross-site scripting (XSS) as the attack vector.
5
Is there a proof of concept for CVE-2024-29921?
Yes, various security research platforms may have proofs of concept demonstrating the exploitation of CVE-2024-29921.