Cross-site scripting (XSS) vulnerability in header.tpl.php in the modern template for Singapore 0.10.1 allows remote attackers to inject arbitrary web script or HTML via the gallery parameter to default.php.
| Software | From | Fixed in |
|---|---|---|
| singapore / singapore | 0.10.1 | 0.10.1.x |
| modern / modern | 1.3.2 | 1.3.2.x |