Lucene search

K
wpvulndbAlex SanfordWPVDB-ID:3B7A7070-8D61-4FF8-B003-B4FF06221635
HistorySep 25, 2023 - 12:00 a.m.

NextGEN Gallery < 3.39 - Admin+ Local File Inclusion

2023-09-2500:00:00
Alex Sanford
wpscan.com
4
nextgen gallery
3.39
admin
local file inclusion
lfi attacks
security

EPSS

0.001

Percentile

23.9%

Description The plugin does not validate some block attributes before using them to generate paths passed to include function/s, allowing Admin users to perform LFI attacks

PoC

1. Create a gallery and upload an image. 2. Add the NextGEN Gallery block to a page and click Edit. Select the Gallery created in the previous step. 3. In “Customize Display Settings”, using the developer tools, set the value of the “Select View” field to “default/…/…/…/…/…/…/…/…/…/…/…/…/…/…/…/…/…/…/…/…/…/…/…/…/…/…/…/…/etc/passwd” 4. Save and load the page to view the contents of /etc/passwd.

EPSS

0.001

Percentile

23.9%

Related for WPVDB-ID:3B7A7070-8D61-4FF8-B003-B4FF06221635