### [CVE-2018-1000172](https://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2018-1000172) ![](https://img.shields.io/static/v1?label=Product&message=n%2Fa&color=blue) ![](https://img.shields.io/static/v1?label=Version&message=n%2Fa&color=blue) ![](https://img.shields.io/static/v1?label=Vulnerability&message=n%2Fa&color=brighgreen) ### Description Imagely NextGEN Gallery version 2.2.30 and earlier contains a Cross Site Scripting (XSS) vulnerability in Image Alt & Title Text. This attack appears to be exploitable via a victim viewing the image in the administrator page. This vulnerability appears to have been fixed in 2.2.45. ### POC #### Reference - https://fortiguard.com/zeroday/FG-VD-17-215 - https://fortiguard.com/zeroday/FG-VD-17-215 #### Github - https://github.com/ARPSyndicate/cvemon