Impact
The vulnerability is a stored cross‑site scripting flaw affecting JoomGallery versions earlier than 4.4.0. An authenticated user with elevated privileges can embed a malicious script into any image in the gallery. When other users view the image, the script runs in their browser, potentially stealing credentials, defacing the site, or delivering malware. This weakness falls under CWE‑79 and directly impacts client‑side confidentiality and integrity.
Affected Systems
The affected product is the JoomGallery extension for Joomla, provided by joomgalleryfriends.net. Versions earlier than 4.4.0 are impacted; no additional version constraints are specified in the advisory.
Risk and Exploitability
The CVSS score of 8.6 indicates high severity. EPSS is not available, so the likelihood of exploitation cannot be quantified precisely, but the vulnerability is exploitable by anyone with privileged access to the image upload interface. The vulnerability is not listed in CISA’s KEV catalog, implying no confirmed active exploitation in the public domain yet. An attacker can target the site by elevating privileges or abusing an existing privileged account, after which the stored payload is served to all visitors.
OpenCVE Enrichment