The File Gallery plugin before 1.7.9.2 for WordPress does not properly escape strings, which allows remote administrators to execute arbitrary PHP code via a \' (backslash quote) in the setting fields to /wp-admin/options-media.php, related to the create_function function.
CVSS 2.0
Severity: MEDIUM
Problem Type: CWE-94,
Products Affected
| Vendor | Product | Version |
|---|---|---|
| skyphe | file-gallery | 1.4 |
| skyphe | file-gallery | 1.5.1 |
| skyphe | file-gallery | 1.6.5.3 |
| skyphe | file-gallery | * |
| skyphe | file-gallery | 1.7.8 |
| skyphe | file-gallery | 1.6.5.5 |
| skyphe | file-gallery | 1.7.5.1 |
| skyphe | file-gallery | 1.6.3 |
| skyphe | file-gallery | 1.6.4 |
| skyphe | file-gallery | 1.6.2 |
| skyphe | file-gallery | 1.6.5.1 |
| skyphe | file-gallery | 1.5.7 |
| skyphe | file-gallery | 1.6.6 |
| skyphe | file-gallery | 1.6.5 |
| skyphe | file-gallery | 1.6.5.6 |
| skyphe | file-gallery | 1.6.5.2 |
| skyphe | file-gallery | 1.5.9 |
| skyphe | file-gallery | 1.5.4 |
| skyphe | file-gallery | 1.6 |
| skyphe | file-gallery | 1.7.2 |
| skyphe | file-gallery | 1.7.6 |
| skyphe | file-gallery | 1.7.5.3 |
| skyphe | file-gallery | 1.5.2 |
| skyphe | file-gallery | 1.7.4.1 |
| skyphe | file-gallery | 1.1 |
| skyphe | file-gallery | 1.5.5 |
| skyphe | file-gallery | 1.7 |
| skyphe | file-gallery | 1.7.7 |
| skyphe | file-gallery | 1.3 |
| skyphe | file-gallery | 1.5.8 |
| skyphe | file-gallery | 1.7.4 |
| skyphe | file-gallery | 1.5.3 |
| skyphe | file-gallery | 1.6.4.1 |
| skyphe | file-gallery | 1.7.3 |
| skyphe | file-gallery | 1.7.5 |
| skyphe | file-gallery | 1.5 |
| skyphe | file-gallery | 1.6.0.1 |
| skyphe | file-gallery | 1.7.1 |
| skyphe | file-gallery | 1.2 |
| skyphe | file-gallery | 1.6.5.4 |
| skyphe | file-gallery | 1.5.6 |
Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting') vulnerability in Bruno "Aesqe" Babic File Gallery allows Reflected XSS.This issue affects File Gallery: from n/a through 1.8.5.4.
CVSS 3.x
| Source | Score | Severity | Vector | Exploitability | Impact |
|---|---|---|---|---|---|
| audit@patchstack.com | 7.1 | HIGH | CVSS:3.1/AV:N/AC:L/PR:N/UI:R/S:C/C:L/I:L/A:L | 2.8 | 3.7 |
| nvd@nist.gov | 6.1 | MEDIUM | CVSS:3.1/AV:N/AC:L/PR:N/UI:R/S:C/C:L/I:L/A:N | 2.8 | 2.7 |
Products Affected
| Vendor | Product | Version |
|---|---|---|
| skyphe | file_gallery | * |