Vulnerability Details CVE-2018-7717
The htmlImageAddTitleAttribute function in sige.php in the Kubik-Rubik Simple Image Gallery Extended (SIGE) extension 3.2.3 for Joomla! has XSS via a crafted image header, as demonstrated by the Caption-Abstract header object in a JPEG file. This is fixed in 3.3.1.
Exploit prediction scoring system (EPSS) score
EPSS Score 0.002
EPSS Ranking 47.2%
CVSS Severity
CVSS v3 Score 6.1
CVSS v2 Score 4.3
Products affected by CVE-2018-7717
-
cpe:2.3:a:kubik-rubik:simple_image_gallery_extended:1.5-15
-
cpe:2.3:a:kubik-rubik:simple_image_gallery_extended:1.5-3
-
cpe:2.3:a:kubik-rubik:simple_image_gallery_extended:1.6-2
-
cpe:2.3:a:kubik-rubik:simple_image_gallery_extended:1.7-2
-
cpe:2.3:a:kubik-rubik:simple_image_gallery_extended:3.2.0