Логотип exploitDog
Консоль
Логотип exploitDog

exploitDog

github логотип

GHSA-f672-mxfg-3p82

Опубликовано: 24 мая 2022
Источник: github
Github: Не прошло ревью
CVSS3: 6.1

Описание

This Gallery from files WordPress plugin through 1.6.0 gives the functionality of uploading images to the server. But filenames are not properly sanitized before being output in an error message when they have an invalid extension, leading to a reflected Cross-Site Scripting issue. Due to the lack of CSRF check, the attack could also be performed via such vector.

This Gallery from files WordPress plugin through 1.6.0 gives the functionality of uploading images to the server. But filenames are not properly sanitized before being output in an error message when they have an invalid extension, leading to a reflected Cross-Site Scripting issue. Due to the lack of CSRF check, the attack could also be performed via such vector.

EPSS

Процентиль: 29%
0.00108
Низкий

6.1 Medium

CVSS3

Дефекты

CWE-352
CWE-79

Связанные уязвимости

CVSS3: 6.1
nvd
больше 4 лет назад

This Gallery from files WordPress plugin through 1.6.0 gives the functionality of uploading images to the server. But filenames are not properly sanitized before being output in an error message when they have an invalid extension, leading to a reflected Cross-Site Scripting issue. Due to the lack of CSRF check, the attack could also be performed via such vector.

EPSS

Процентиль: 29%
0.00108
Низкий

6.1 Medium

CVSS3

Дефекты

CWE-352
CWE-79