Логотип exploitDog
Консоль
Логотип exploitDog

exploitDog

github логотип

GHSA-r879-3456-rvxx

Опубликовано: 08 июл. 2022
Источник: github
Github: Не прошло ревью
CVSS3: 6.5

Описание

In nextgen-galery wordpress plugin before 2.0.77.3 there are two vulnerabilities which can allow an attacker to gain full access over the web application. The vulnerabilities lie in how the application validates user uploaded files and lack of security measures preventing unwanted HTTP requests.

In nextgen-galery wordpress plugin before 2.0.77.3 there are two vulnerabilities which can allow an attacker to gain full access over the web application. The vulnerabilities lie in how the application validates user uploaded files and lack of security measures preventing unwanted HTTP requests.

EPSS

Процентиль: 28%
0.00102
Низкий

6.5 Medium

CVSS3

Дефекты

CWE-352

Связанные уязвимости

CVSS3: 6.5
nvd
больше 3 лет назад

In nextgen-galery wordpress plugin before 2.0.77.3 there are two vulnerabilities which can allow an attacker to gain full access over the web application. The vulnerabilities lie in how the application validates user uploaded files and lack of security measures preventing unwanted HTTP requests.

EPSS

Процентиль: 28%
0.00102
Низкий

6.5 Medium

CVSS3

Дефекты

CWE-352