Cross-site scripting vulnerability exists in Simple Image Sizes 3.2.3 and earlier. If this vulnerability is exploited, an arbitrary script may be executed on the web browser of the user who is logging in to the product with the administrative privilege and accessing the settings screen.
History

Tue, 28 Jan 2025 15:15:00 +0000

Type Values Removed Values Added
Metrics ssvc

{'options': {'Automatable': 'no', 'Exploitation': 'none', 'Technical Impact': 'partial'}, 'version': '2.0.3'}


Tue, 28 Jan 2025 04:45:00 +0000

Type Values Removed Values Added
Description Cross-site scripting vulnerability exists in Simple Image Sizes 3.2.3 and earlier. If this vulnerability is exploited, an arbitrary script may be executed on the web browser of the user who is logging in to the product with the administrative privilege and accessing the settings screen.
Weaknesses CWE-79
References
Metrics cvssV3_0

{'score': 4.8, 'vector': 'CVSS:3.0/AV:N/AC:L/PR:H/UI:R/S:C/C:L/I:L/A:N'}


cve-icon MITRE

Status: PUBLISHED

Assigner: jpcert

Published: 2025-01-28T04:36:53.852Z

Updated: 2025-01-28T14:59:09.996Z

Reserved: 2025-01-24T05:18:38.886Z

Link: CVE-2025-24810

cve-icon Vulnrichment

Updated: 2025-01-28T14:59:05.803Z

cve-icon NVD

Status : Deferred

Published: 2025-01-28T05:15:11.413

Modified: 2026-04-15T00:35:42.020

Link: CVE-2025-24810

cve-icon Redhat

No data.