Cross-site scripting vulnerability exists in Simple Image Sizes 3.2.3 and earlier. If this vulnerability is exploited, an arbitrary script may be executed on the web browser of the user who is logging in to the product with the administrative privilege and accessing the settings screen.
Advisories
Source ID Title
EUVD EUVD EUVD-2025-3950 Cross-site scripting vulnerability exists in Simple Image Sizes 3.2.3 and earlier. If this vulnerability is exploited, an arbitrary script may be executed on the web browser of the user who is logging in to the product with the administrative privilege and accessing the settings screen.
Fixes

Solution

No solution given by the vendor.


Workaround

No workaround given by the vendor.

History

Tue, 28 Jan 2025 15:15:00 +0000

Type Values Removed Values Added
Metrics ssvc

{'options': {'Automatable': 'no', 'Exploitation': 'none', 'Technical Impact': 'partial'}, 'version': '2.0.3'}


Tue, 28 Jan 2025 04:45:00 +0000

Type Values Removed Values Added
Description Cross-site scripting vulnerability exists in Simple Image Sizes 3.2.3 and earlier. If this vulnerability is exploited, an arbitrary script may be executed on the web browser of the user who is logging in to the product with the administrative privilege and accessing the settings screen.
Weaknesses CWE-79
References
Metrics cvssV3_0

{'score': 4.8, 'vector': 'CVSS:3.0/AV:N/AC:L/PR:H/UI:R/S:C/C:L/I:L/A:N'}


Projects

Sign in to view the affected projects.

cve-icon MITRE

Status: PUBLISHED

Assigner: jpcert

Published:

Updated: 2025-01-28T14:59:09.996Z

Reserved: 2025-01-24T05:18:38.886Z

Link: CVE-2025-24810

cve-icon Vulnrichment

Updated: 2025-01-28T14:59:05.803Z

cve-icon NVD

Status : Received

Published: 2025-01-28T05:15:11.413

Modified: 2025-01-28T05:15:11.413

Link: CVE-2025-24810

cve-icon Redhat

No data.

cve-icon OpenCVE Enrichment

No data.

Weaknesses