Vulnerability Description
XSS exists in the Tribulant Slideshow Gallery plugin 1.6.8 for WordPress via the wp-admin/admin.php?page=slideshow-galleries&method=save Gallery[id] or Gallery[title] parameter.
CVSS Score
MEDIUM
Affected Products
| Vendor | Product | Versions |
|---|---|---|
| Tribulant | Slideshow Gallery | 1.6.8 |
Related Weaknesses (CWE)
References
- https://ansawaf.blogspot.com/2019/04/xss-and-sqli-in-slideshow-gallery.htmlExploitThird Party Advisory
- https://docs.google.com/document/d/1rwN4hJkD5TJfCa16rsGwzYhzL-ODd2VLkFnPvAIq4Ys/Permissions RequiredThird Party Advisory
- https://ansawaf.blogspot.com/2019/04/xss-and-sqli-in-slideshow-gallery.htmlExploitThird Party Advisory
- https://docs.google.com/document/d/1rwN4hJkD5TJfCa16rsGwzYhzL-ODd2VLkFnPvAIq4Ys/Permissions RequiredThird Party Advisory
FAQ
What is CVE-2018-18017?
CVE-2018-18017 is a vulnerability with a CVSS score of 6.1 (MEDIUM). XSS exists in the Tribulant Slideshow Gallery plugin 1.6.8 for WordPress via the wp-admin/admin.php?page=slideshow-galleries&method=save Gallery[id] or Gallery[title] parameter.
How severe is CVE-2018-18017?
CVE-2018-18017 has been rated MEDIUM with a CVSS base score of 6.1/10. Review the CVSS metrics above for detailed severity breakdown.
Is there a patch for CVE-2018-18017?
Check the references section above for vendor advisories and patch information. Affected products include: Tribulant Slideshow Gallery.