NextGEN Gallery Pro < 3.1.11 - Reflected Cross-Site Scripting (XSS)
CVE-2021-24293

6.1MEDIUM

Key Information:

Vendor
Wordpress
Vendor
CVE Published:
5 May 2021

Summary

In the eCommerce module of the NextGEN Gallery Pro WordPress plugin before 3.1.11, there is an action to call get_cart_items via photocrati_ajax , after that the settings[shipping_address][name] is able to inject malicious javascript.

Affected Version(s)

NextGen Gallery Pro 3.1.11

References

CVSS V3.1

Score:
6.1
Severity:
MEDIUM
Confidentiality:
Low
Integrity:
Low
Availability:
Low
Attack Vector:
Network
Attack Complexity:
Low
Privileges Required:
None
User Interaction:
Required
Scope:
Changed

Timeline

  • Vulnerability published

  • Vulnerability Reserved

Credit

mgthuramoemyint
.