First published: Sun Oct 06 2024(Updated: )
Improper Neutralization of Input During Web Page Generation (XSS or 'Cross-site Scripting') vulnerability in 10Web Photo Gallery by 10Web allows Stored XSS.This issue affects Photo Gallery by 10Web: from n/a through 1.8.27.
Credit: audit@patchstack.com
Affected Software | Affected Version | How to fix |
---|---|---|
10quality Post Gallery | <=1.8.27 | |
10Web Photo Gallery | <=1.8.27 | |
10quality Post Gallery | <1.8.28 |
Update to 1.8.28 or a higher version.
Sign up to SecAlerts for real-time vulnerability data matched to your software, aggregated from hundreds of sources.
The severity of CVE-2024-44043 is classified as a medium risk due to the potential for Stored XSS attacks.
To fix CVE-2024-44043, update the 10Web Photo Gallery plugin to version 1.8.28 or higher.
CVE-2024-44043 affects versions of 10Web Photo Gallery up to and including 1.8.27.
CVE-2024-44043 is a cross-site scripting (XSS) vulnerability that allows attackers to inject malicious scripts.
CVE-2024-44043 is classified as a Stored XSS vulnerability, meaning the malicious script can be stored on the server.