PT-2021-11874 · WordPress · Nextgen Gallery
Published
2021-02-09
·
Updated
2021-07-21
·
CVE-2020-35942
CVSS v3.1
8.8
High
| Vector | AV:N/AC:L/PR:N/UI:R/S:U/C:H/I:H/A:H |
Name of the Vulnerable Software and Affected Versions:
NextGEN Gallery plugin versions prior to 3.5.0
Description:
A Cross-Site Request Forgery (CSRF) issue allows File Upload and Local File Inclusion via settings modification, leading to Remote Code Execution and XSS. It is possible to bypass CSRF protection by not including a
nonce parameter.Recommendations:
For NextGEN Gallery plugin versions prior to 3.5.0, update to version 3.5.0 or later to resolve the issue. As a temporary workaround, consider disabling the file upload feature and restricting settings modification until a patch is available. Avoid using the
nonce parameter in a way that could be exploited to bypass CSRF protection.Exploit
Fix
RCE
XSS
CSRF
Found an issue in the description? Have something to add? Feel free to write us 👾
Related Identifiers
Affected Products
Nextgen Gallery