CVE-2020-35943
09.02.2021, 18:15
A Cross-Site Request Forgery (CSRF) issue in the NextGEN Gallery plugin before 3.5.0 for WordPress allows File Upload. (It is possible to bypass CSRF protection by simply not including a nonce parameter.)
Vendor | Product | Version |
---|---|---|
imagely | nextgen_gallery | 𝑥 < 3.5.0 |
𝑥
= Vulnerable software versions
Common Weakness Enumeration