CVE-2024-32583: WordPress Photo Gallery by 10Web plugin <= 1.8.21 - Reflected Cross Site Scripting (XSS) vulnerability
Published Apr 18, 2024
·Updated
Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting') vulnerability in Photo Gallery Team Photo Gallery by 10Web allows Reflected XSS.This issue affects Photo Gallery by 10Web: from n/a through 1.8.21.
Affected Software
2 affected components
10web Photo Gallery<=1.8.21
10web Photo Gallery Wordpress<1.8.22
Remediation
Information
Update to 1.8.22 or a higher version.
Event History
Apr 18, 2024
CVE Published
via MITRE·09:20 AM
Data Sourced
via MITRE·09:20 AM
RemedyDescriptionSeverityWeakness
Data Sourced
via NVD·10:15 AM
DescriptionSeverityWeaknessAffected Software
Frequently Asked Questions
1
What is the severity of CVE-2024-32583?
CVE-2024-32583 is classified as a reflected Cross-site Scripting (XSS) vulnerability.
2
How do I fix CVE-2024-32583?
To fix CVE-2024-32583, upgrade the Photo Gallery by 10Web to version 1.8.22 or later.
3
What versions of Photo Gallery by 10Web are affected by CVE-2024-32583?
CVE-2024-32583 affects Photo Gallery by 10Web versions up to and including 1.8.21.
4
How does CVE-2024-32583 impact users?
CVE-2024-32583 allows attackers to execute arbitrary JavaScript in the context of a user's browser.
5
What is Cross-site Scripting in relation to CVE-2024-32583?
Cross-site Scripting, as seen in CVE-2024-32583, involves injecting malicious scripts into web pages viewed by users.