First published: Mon Apr 15 2019(Updated: )
XSS exists in the Tribulant Slideshow Gallery plugin 1.6.8 for WordPress via the wp-admin/admin.php?page=slideshow-galleries&method=save Gallery[id] or Gallery[title] parameter.
Credit: cve@mitre.org
Affected Software | Affected Version | How to fix |
---|---|---|
Tribulant Slideshow Gallery | =1.6.8 |
Sign up to SecAlerts for real-time vulnerability data matched to your software, aggregated from hundreds of sources.
The vulnerability ID is CVE-2018-18017.
The title of this vulnerability is 'XSS exists in the Tribulant Slideshow Gallery plugin 1.6.8 for WordPress via the wp-admin/admin.php'.
The vulnerability can be exploited through the wp-admin/admin.php page with the Gallery[id] or Gallery[title] parameter.
The severity of CVE-2018-18017 is medium.
To fix the vulnerability, update the Tribulant Slideshow Gallery plugin to version 1.6.9 or later.