PT-2023-10164 · WordPress · Fancy Gallery Plugin
CVE-2014-125096
·
Publicado
2023-04-10
·
Atualizado
2024-05-17
CVSS v2.0
4.0
Média
| Vetor | AV:N/AC:L/Au:S/C:N/I:P/A:N |
Name of the Vulnerable Software and Affected Versions
Fancy Gallery Plugin version 1.5.12
Description
A vulnerability was found in the Fancy Gallery Plugin on WordPress, affecting an unknown functionality of the file class.options.php of the component Options Page. The manipulation leads to cross site scripting. The attack can be launched remotely. Upgrading to version 1.5.13 is able to address this issue.
Recommendations
For Fancy Gallery Plugin version 1.5.12, upgrade to version 1.5.13 to address the issue. As a temporary workaround, consider restricting access to the
class.options.php file until the upgrade is applied.Correção
XSS
Encontrou algum problema na descrição? Tem algo a acrescentar? Fique à vontade para nos escrever 👾
Enumeração de Fraquezas
Identificadores relacionados
Produtos afetados
Fancy Gallery Plugin