The link of the upload page of the front end took its target from the address of the page (parameter return, base64 encoded) and printed it into the page without checking or escaping it. A prepared link could make it point to another web site, or run a script in the page, in the session of the user who opened it.
- Needed: no account. The victim is logged in to the front end with the permission Edit of Event Gallery - only such a user sees the upload page - and opens a prepared link.
- Affected: 3.11.4, which brought the upload in the front end, up to 6.0.0. The free edition is affected as well. 4.3.3 is not affected.
- Fixed in: 6.5.0 and 4.3.3. The link only leads to a page of your own site and is left out otherwise, and it is escaped.
-
Severity: CVSS 4.0 5.3 (
CVSS:4.0/AV:N/AC:L/AT:N/PR:N/UI:P/VC:L/VI:L/VA:L/SC:N/SI:N/SA:N), CWE-79 and CWE-601. - CVE: CVE-2026-97165.
All prices include VAT. The gross price will vary depending on the selected shipping country.