Lucene search

K
vulnrichmentWPScanVULNRICHMENT:CVE-2023-3154
HistoryOct 16, 2023 - 7:39 p.m.

CVE-2023-3154 NextGEN Gallery < 3.39 - Admin+ PHAR Deserialization

2023-10-1619:39:06
WPScan
github.com
1
wordpress
nextgen gallery
v3.39
phar deserialization
vulnerable
arbitrary resources

SSVC

Exploitation

poc

Automatable

yes

Technical Impact

partial

The WordPress Gallery Plugin WordPress plugin before 3.39 is vulnerable to PHAR Deserialization due to a lack of input parameter validation in the gallery_edit function, allowing an attacker to access arbitrary resources on the server.

ADP Affected

[
  {
    "cpes": [
      "cpe:2.3:a:imagely:nextgen_gallery:*:*:*:*:*:*:*:*"
    ],
    "vendor": "imagely",
    "product": "nextgen_gallery",
    "versions": [
      {
        "status": "affected",
        "version": "0",
        "lessThan": "3.39",
        "versionType": "custom"
      }
    ],
    "defaultStatus": "unknown"
  }
]

SSVC

Exploitation

poc

Automatable

yes

Technical Impact

partial

Related for VULNRICHMENT:CVE-2023-3154