Логотип exploitDog
Консоль
Логотип exploitDog

exploitDog

github логотип

GHSA-4gvq-h6xw-fx34

Опубликовано: 22 фев. 2022
Источник: github
Github: Не прошло ревью

Описание

The Image Photo Gallery Final Tiles Grid WordPress plugin before 3.5.3 does not sanitise and escape the Description field when editing a gallery, allowing users with a role as low as contributor to perform Cross-Site Scripting attacks against other users having access to the gallery dashboard

The Image Photo Gallery Final Tiles Grid WordPress plugin before 3.5.3 does not sanitise and escape the Description field when editing a gallery, allowing users with a role as low as contributor to perform Cross-Site Scripting attacks against other users having access to the gallery dashboard

EPSS

Процентиль: 40%
0.0018
Низкий

Дефекты

CWE-79

Связанные уязвимости

CVSS3: 5.4
nvd
почти 4 года назад

The Image Photo Gallery Final Tiles Grid WordPress plugin before 3.5.3 does not sanitise and escape the Description field when editing a gallery, allowing users with a role as low as contributor to perform Cross-Site Scripting attacks against other users having access to the gallery dashboard

EPSS

Процентиль: 40%
0.0018
Низкий

Дефекты

CWE-79