Cross-Site Scripting Vulnerability in TinyWebGallery by TinyWebGallery
CVE-2017-16635

5.4MEDIUM

Key Information:

Vendor
CVE Published:
6 November 2017

What is CVE-2017-16635?

In TinyWebGallery version 2.4, an XSS vulnerability exists within the mkname, mkitem, and item parameters of the Add/Create module. This flaw allows remote attackers with low-level user privileges to execute malicious scripts through input fields in the TWG Explorer item listing. By utilizing a POST request, attackers can inject harmful code, which is executed when items are added or created, posing a significant threat to the integrity of the application and its users.

References

CVSS V3.1

Score:
5.4
Severity:
MEDIUM
Confidentiality:
Low
Integrity:
Low
Availability:
Low
Attack Vector:
Network
Attack Complexity:
Low
Privileges Required:
Low
User Interaction:
Required
Scope:
Changed

Timeline

  • Vulnerability published

  • Vulnerability Reserved

.