Lucene search

K
patchstackAm!rPATCHSTACK:17012189DA580DAB082B1F62F3332F85
HistoryDec 12, 2011 - 12:00 a.m.

WordPress Grand FlAGallery Plugin 1.57 - Cross Site Scripting

2011-12-1200:00:00
Am!r
patchstack.com
7

EPSS

0.004

Percentile

75.1%

WordPress Grand FlAGallery plugin’s “flagshow.php” parameter is prone to a cross-site scripting vulnerability. It fails to properly clean up user-supplied input. An attacker may execute arbitrary script code in the browser of an user in the context of the affected site. In this way the attacker can steal cookie-based authentication credentials. Other attacks are also possible.

Solution

           Update the plugin. 

EPSS

0.004

Percentile

75.1%

Related for PATCHSTACK:17012189DA580DAB082B1F62F3332F85