CVE-2018-18017: XSS
Published Apr 15, 2019
·Updated
XSS exists in the Tribulant Slideshow Gallery plugin 1.6.8 for WordPress via the wp-admin/admin.php?page=slideshow-galleries&method=save Gallery[id] or Gallery[title] parameter.
Affected Software
1 affected component
Tribulant Slideshow Gallery Wordpress=1.6.8
Event History
Apr 15, 2019
CVE Published
via MITRE·08:24 PM
Data Sourced
via MITRE·08:24 PM
Description
Frequently Asked Questions
1
What is the vulnerability ID of this vulnerability?
The vulnerability ID is CVE-2018-18017.
2
What is the title of this vulnerability?
The title of this vulnerability is 'XSS exists in the Tribulant Slideshow Gallery plugin 1.6.8 for WordPress via the wp-admin/admin.php'.
3
How can the vulnerability be exploited?
The vulnerability can be exploited through the wp-admin/admin.php page with the Gallery[id] or Gallery[title] parameter.
4
What is the severity of CVE-2018-18017?
The severity of CVE-2018-18017 is medium.
5
How do I fix the vulnerability?
To fix the vulnerability, update the Tribulant Slideshow Gallery plugin to version 1.6.9 or later.