CVE-2021-24293
05.05.2021, 19:15
In the eCommerce module of the NextGEN Gallery Pro WordPress plugin before 3.1.11, there is an action to call get_cart_items via photocrati_ajax , after that the settings[shipping_address][name] is able to inject malicious javascript.
Vendor | Product | Version |
---|---|---|
imagely | nextgen_gallery | 𝑥 < 3.1.11 |
𝑥
= Vulnerable software versions