Stored XSS Vulnerability in Modula Image Gallery for WordPress
CVE-2020-9003
5.4MEDIUM
Summary
A stored XSS vulnerability exists in the Modula Image Gallery plugin for WordPress, affecting versions before 2.2.5. This vulnerability allows an authenticated low-privileged user to inject arbitrary JavaScript code. When this malicious code is executed by other users who view the affected images, it can lead to unauthorized actions or data theft, compromising the integrity and security of the website.
References
CVSS V3.1
Score:
5.4
Severity:
MEDIUM
Confidentiality:
Low
Integrity:
Low
Availability:
Low
Attack Vector:
Network
Attack Complexity:
Low
Privileges Required:
Low
User Interaction:
Required
Scope:
Changed
Timeline
Vulnerability published
Vulnerability Reserved