CVE-2021-24293: NextGEN Gallery Pro < 3.1.11 - Reflected Cross-Site Scripting (XSS)
Published May 5, 2021
·Updated
In the eCommerce module of the NextGEN Gallery Pro WordPress plugin before 3.1.11, there is an action to call getcartitems via photocratiajax , after that the settings[shippingaddress][name] is able to inject malicious javascript.
Affected Software
1 affected component
Imagely Nextgen Gallery Wordpress<3.1.11
Event History
May 5, 2021
CVE Published
via MITRE·06:28 PM
Data Sourced
via MITRE·06:28 PM
DescriptionWeakness
Frequently Asked Questions
1
What is the vulnerability ID for this vulnerability?
The vulnerability ID for this vulnerability is CVE-2021-24293.
2
What is the severity level of CVE-2021-24293?
The severity level of CVE-2021-24293 is medium.
3
What is the affected software for CVE-2021-24293?
The affected software for CVE-2021-24293 is the NextGEN Gallery Pro WordPress plugin before version 3.1.11.
4
What is the CWE ID for CVE-2021-24293?
The CWE ID for CVE-2021-24293 is CWE-79.
5
How can I fix CVE-2021-24293?
To fix CVE-2021-24293, update the NextGEN Gallery Pro WordPress plugin to version 3.1.11 or later.