CVE-2015-9229: XSS
Published Sep 12, 2017
·Updated
In the nggallery-manage-gallery page in the Photocrati NextGEN Gallery plugin 2.1.15 for WordPress, XSS is possible for remote authenticated administrators via the images[1][alttext] parameter.
Affected Software
1 affected component
Imagely Nextgen Gallery Wordpress=2.1.15
Event History
Sep 12, 2017
CVE Published
via MITRE·10:00 PM
Data Sourced
via MITRE·10:00 PM
Description
Frequently Asked Questions
1
What is the severity of CVE-2015-9229?
CVE-2015-9229 has a medium severity rating due to its potential for XSS attacks affecting remote authenticated administrators.
2
How do I fix CVE-2015-9229?
To fix CVE-2015-9229, upgrade the Photocrati NextGEN Gallery plugin to version 2.1.16 or later.
3
Who is affected by CVE-2015-9229?
CVE-2015-9229 affects remote authenticated administrators using Photocrati NextGEN Gallery version 2.1.15 for WordPress.
4
What type of vulnerability is CVE-2015-9229?
CVE-2015-9229 is a Cross-Site Scripting (XSS) vulnerability.
5
Can CVE-2015-9229 lead to data compromise?
Yes, CVE-2015-9229 can potentially lead to data compromise through malicious scripts executed in the context of authenticated sessions.