← Back

CVE-2020-35942

nvd nist
Published: Feb 9, 2021Modified: Nov 21, 2024

JSON object

Loading...
8.8
Vector
CVSS:3.1/AV:N/AC:L/PR:N/UI:R/S:U/C:H/I:H/A:H
Exploitability: 2.8 / Impact: 5.9
Source: NVD

Description

A Cross-Site Request Forgery (CSRF) issue in the NextGEN Gallery plugin before 3.5.0 for WordPress allows File Upload and Local File Inclusion via settings modification, leading to Remote Code Execution and XSS. (It is possible to bypass CSRF protection by simply not including a nonce parameter.)

Affected (1)

1 product
Nextgen Gallery
Configuration A
1 vulnerable
Vulnerable SoftwareAffected Versions
Before 3.5.0

Timeline

No history available yet.