First published: Fri Oct 21 2016(Updated: )
XSS & SQLi in HugeIT slideshow v1.0.4
Credit: cve@mitre.org
Affected Software | Affected Version | How to fix |
---|---|---|
Huge-it Slideshow | =1.0.4 |
Sign up to SecAlerts for real-time vulnerability data matched to your software, aggregated from hundreds of sources.
CVE-2016-1000117 has a medium severity rating primarily due to its potential for XSS and SQL injection vulnerabilities.
To fix CVE-2016-1000117, upgrade the HugeIT slideshow extension to the latest version provided by the vendor.
CVE-2016-1000117 contains Cross-Site Scripting (XSS) and SQL Injection vulnerabilities.
CVE-2016-1000117 specifically affects HugeIT Slideshow version 1.0.4.
The impact of CVE-2016-1000117 can allow an attacker to execute arbitrary scripts or manipulate database queries, potentially compromising the application and gaining unauthorized access.