CVE-2023-5307: Photos and Files Contest Gallery – Contact Form < 21.2.8.1 - Unauthenticated Stored XSS via HTTP Headers
Published Oct 31, 2023
·Updated
The Photos and Files Contest Gallery WordPress plugin before 21.2.8.1 does not sanitise and escape some parameters, which could allow unauthenticated users to perform Cross-Site Scripting attacks via certain headers.
Affected Software
1 affected component
contest-gallery Contest Gallery Wordpress<21.2.8.1
Event History
Oct 31, 2023
CVE Published
via MITRE·01:54 PM
Data Sourced
via MITRE·01:54 PM
DescriptionWeakness
Data Sourced
via NVD·02:15 PM
DescriptionSeverityWeaknessAffected Software
Frequently Asked Questions
1
What is the vulnerability ID of this vulnerability?
The vulnerability ID of this vulnerability is CVE-2023-5307.
2
What is the severity of CVE-2023-5307?
The severity of CVE-2023-5307 is medium.
3
How does CVE-2023-5307 affect the Photos and Files Contest Gallery WordPress plugin?
CVE-2023-5307 affects the Photos and Files Contest Gallery WordPress plugin before version 21.2.8.1.
4
What is the CWE ID associated with CVE-2023-5307?
The CWE ID associated with CVE-2023-5307 is CWE-79.
5
How can an unauthenticated user exploit CVE-2023-5307?
An unauthenticated user can exploit CVE-2023-5307 by performing Cross-Site Scripting (XSS) attacks via certain headers.