CVE-2023-53939
MEDIUMTinyWebGallery 2.5 - Authenticated Stored Cross-Site Scripting via Folder Name Parameter
Title source: llmExploitation Summary
EIP tracks 1 public exploit for CVE-2023-53939. PoCs published by Mirabbas Ağalarov.
AI-analyzed exploit summary This exploit demonstrates a stored XSS vulnerability in TinyWebGallery v2.5 by injecting a malicious script into the folder name field, which is then executed when the page is loaded.
Description
TinyWebGallery v2.5 contains a stored cross-site scripting vulnerability that allows authenticated attackers to inject malicious scripts through the folder name parameter. Attackers can edit album folder names with script tags to execute arbitrary JavaScript when other users view the affected gallery pages.
Exploits (1)
This exploit demonstrates a stored XSS vulnerability in TinyWebGallery v2.5 by injecting a malicious script into the folder name field, which is then executed when the page is loaded.
References (3)
Scores
CVSS:3.1/AV:N/AC:L/PR:L/UI:R/S:C/C:L/I:L/A:N