CVE-2024-37442: WordPress Photo Gallery by Ays – Responsive Image Gallery plugin < 5.7.1 - HTML Injection vulnerability
Published Jul 9, 2024
·Updated
Improper Neutralization of Special Elements in Output Used by a Downstream Component ('Injection') vulnerability in Photo Gallery Team Photo Gallery by Ays allows Code Injection.This issue affects Photo Gallery by Ays: from n/a before 5.7.1.
Affected Software
1 affected component
ays-pro Photo Gallery Wordpress<5.7.1
Remediation
Information
Update to 5.7.1 or a higher version.
Event History
Jul 9, 2024
CVE Published
via MITRE·10:42 AM
Data Sourced
via MITRE·10:42 AM
RemedyDescriptionSeverityWeakness
Data Sourced
via NVD·11:15 AM
DescriptionSeverityWeakness
Frequently Asked Questions
1
What is the severity of CVE-2024-37442?
CVE-2024-37442 is classified as a high severity vulnerability due to its potential for code injection.
2
How do I fix CVE-2024-37442?
To fix CVE-2024-37442, update Photo Gallery by Ays to version 5.7.1 or later.
3
What kind of vulnerability is CVE-2024-37442?
CVE-2024-37442 is an injection vulnerability caused by improper neutralization of special elements in output.
4
Which versions of Photo Gallery by Ays are affected by CVE-2024-37442?
CVE-2024-37442 affects all versions of Photo Gallery by Ays prior to 5.7.1.
5
What are the potential impacts of CVE-2024-37442?
The potential impacts of CVE-2024-37442 include unauthorized code execution and system compromise.