TinyWebGallery v2.5 contains a stored cross-site scripting vulnerability that allows authenticated attackers to inject malicious scripts through the folder name parameter. Attackers can edit album folder names with script tags to execute arbitrary JavaScript when other users view the affected gallery pages.
Metrics
Affected Vendors & Products
References
History
Thu, 18 Dec 2025 22:15:00 +0000
| Type | Values Removed | Values Added |
|---|---|---|
| Metrics |
ssvc
|
Thu, 18 Dec 2025 20:00:00 +0000
| Type | Values Removed | Values Added |
|---|---|---|
| Description | TinyWebGallery v2.5 contains a stored cross-site scripting vulnerability that allows authenticated attackers to inject malicious scripts through the folder name parameter. Attackers can edit album folder names with script tags to execute arbitrary JavaScript when other users view the affected gallery pages. | |
| Title | TinyWebGallery v2.5 Stored Cross-Site Scripting via Folder Name Parameter | |
| Weaknesses | CWE-79 | |
| References |
| |
| Metrics |
cvssV3_1
|
Status: PUBLISHED
Assigner: VulnCheck
Published:
Updated: 2025-12-18T21:46:58.131Z
Reserved: 2025-12-16T19:22:09.997Z
Link: CVE-2023-53939
Updated: 2025-12-18T21:03:34.910Z
Status : Received
Published: 2025-12-18T20:15:52.323
Modified: 2025-12-18T22:15:54.520
Link: CVE-2023-53939
No data.
OpenCVE Enrichment
No data.