Cross-Site Scripting Vulnerability in TinyWebGallery by TinyWebGallery
CVE-2017-16635
5.4MEDIUM
What is CVE-2017-16635?
In TinyWebGallery version 2.4, an XSS vulnerability exists within the mkname, mkitem, and item parameters of the Add/Create module. This flaw allows remote attackers with low-level user privileges to execute malicious scripts through input fields in the TWG Explorer item listing. By utilizing a POST request, attackers can inject harmful code, which is executed when items are added or created, posing a significant threat to the integrity of the application and its users.
