Логотип exploitDog
Консоль
Логотип exploitDog

exploitDog

github логотип

GHSA-7vwp-37h2-j956

Опубликовано: 08 июл. 2022
Источник: github
Github: Не прошло ревью
CVSS3: 8.8

Описание

In nextgen-galery wordpress plugin before 2.0.77.3 there are two vulnerabilities which can allow an attacker to gain full access over the web application. The vulnerabilities lie in how the application validates user uploaded files and lack of security measures preventing unwanted HTTP requests.

In nextgen-galery wordpress plugin before 2.0.77.3 there are two vulnerabilities which can allow an attacker to gain full access over the web application. The vulnerabilities lie in how the application validates user uploaded files and lack of security measures preventing unwanted HTTP requests.

EPSS

Процентиль: 78%
0.01178
Низкий

8.8 High

CVSS3

Дефекты

CWE-434

Связанные уязвимости

CVSS3: 8.8
nvd
больше 3 лет назад

In nextgen-galery wordpress plugin before 2.0.77.3 there are two vulnerabilities which can allow an attacker to gain full access over the web application. The vulnerabilities lie in how the application validates user uploaded files and lack of security measures preventing unwanted HTTP requests.

EPSS

Процентиль: 78%
0.01178
Низкий

8.8 High

CVSS3

Дефекты

CWE-434