PT-2021-11808 · Unknown · Envira Gallery Lite
Published
2021-01-13
·
Updated
2021-01-15
·
CVE-2020-35581
CVSS v3.1
5.4
Medium
| Vector | AV:N/AC:L/PR:L/UI:R/S:C/C:L/I:L/A:N |
Name of the Vulnerable Software and Affected Versions:
Envira Gallery Lite versions prior to 1.8.3.3
Description:
A stored cross-site scripting (XSS) issue allows remote attackers to inject arbitrary JavaScript/HTML code via a POST "/wp-admin/admin-ajax.php" request with the
meta[title] parameter.Recommendations:
For Envira Gallery Lite versions prior to 1.8.3.3, update to version 1.8.3.3 or later to resolve the issue.
As a temporary workaround, consider restricting access to the "/wp-admin/admin-ajax.php" endpoint to minimize the risk of exploitation.
Avoid using the
meta[title] parameter in the affected API endpoint until the issue is resolved.Exploit
Fix
XSS
Found an issue in the description? Have something to add? Feel free to write us 👾
Weakness Enumeration
Related Identifiers
Affected Products
Envira Gallery Lite