PT-2020-7949 · Huge It · Huge-It Gallery-Images Plugin

Gwendal Le Coguic

·

Published

2020-01-21

·

Updated

2020-02-06

·

CVE-2016-11018

CVSS v3.1

9.8

Critical

VectorAV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H
Name of the Vulnerable Software and Affected Versions: Huge-IT gallery-images plugin versions prior to 1.9.0
Description: An issue was discovered in the Huge-IT gallery-images plugin, where the headers Client-Ip and X-Forwarded-For are prone to unauthenticated SQL injection. The affected file is gallery-images.php, and the affected function is huge it image gallery ajax callback().
Recommendations: For versions prior to 1.9.0, update to version 1.9.0 or later to resolve the issue. As a temporary workaround, consider restricting access to the huge it image gallery ajax callback() function until a patch is available. Avoid using the Client-Ip and X-Forwarded-For headers in the affected API endpoint until the issue is resolved.

Exploit

Fix

SQL injection

Found an issue in the description? Have something to add? Feel free to write us 👾

Weakness Enumeration

Related Identifiers

CVE-2016-11018

Affected Products

Huge-It Gallery-Images Plugin