CVE-2015-2324
5.4
Vector
CVSS:3.0/AV:N/AC:L/PR:L/UI:R/S:C/C:L/I:L/A:N
Exploitability: 2.3 / Impact: 2.7
Source: NVD
Description
Cross-site scripting (XSS) vulnerability in the filemanager in the Photo Gallery plugin before 1.2.13 for WordPress allows remote authenticated users with edit permission to inject arbitrary web script or HTML via unspecified vectors.
Affected (1)
Products: 10web: Photo Gallery
Configuration A
| Vulnerable Software | Affected Versions |
|---|---|
| Before 1.2.13 |
References (4)
Source: cve@mitre.org
ProductRelease Notes
Source: af854a3a-2127-422b-91ae-364da2661108
Third Party Advisory
Source: af854a3a-2127-422b-91ae-364da2661108
ProductRelease Notes
Timeline
No history available yet.