nvd.nist.gov
https://nvd.nist.gov/vuln/detail/CVE-2019-15829 CVE-2019-15829
MEDIUMNuclei
Gallery Photoblocks < 1.1.43 - Cross-Site Scripting
Record summary
CVE-2019-15829 has a selected CVSS score of 4.8 (medium); EIP currently links 1 Nuclei template.
Description
The photoblocks-grid-gallery plugin before 1.1.33 for WordPress has wp-admin/admin.php?page=photoblocks-edit&id= XSS.
Description source: CVE List
Exploitation context
Available material
- Nuclei templates
- 1
Nuclei templates
1ProjectDiscoveryMEDIUMGallery Photoblocks < 1.1.43 - Cross-Site ScriptingCVSS 4.8
The Gallery PhotoBlocks WordPress plugin was affected by an Authenticated Reflected XSS security vulnerability.
Impact
Authenticated attackers can inject malicious JavaScript through the id parameter, potentially stealing admin session cookies or performing privileged actions on behalf of administrators.
Remediation
Fixed in 1.1.43
WeaknessesCWE-79
Authorsr3Y3r53
Template tagscvecve2019wpwordpresswp-pluginphotoblocks-galleryxssauthenticatedwpscangreentreelabsvuln
CVSS vector: CVSS:3.0/AV:N/AC:L/PR:H/UI:R/S:C/C:L/I:L/A:N
CPE: cpe:2.3:a:greentreelabs:gallery_photoblocks:*:*:*:*:*:wordpress:*:*
Shodan: http.html:/wp-content/plugins/photoblocks-grid-gallery/
FOFA: body=/wp-content/plugins/photoblocks-grid-gallery/
https://wpscan.com/vulnerability/b8d1d88e-f2e5-4212-af34-c91f563f07b6/ https://nvd.nist.gov/vuln/detail/CVE-2019-15829 https://wordpress.org/plugins/photoblocks-grid-gallery/ https://wordpress.org/plugins/photoblocks-grid-gallery/#developers https://wpvulndb.com/vulnerabilities/9443
Source: ProjectDiscovery
References
3wordpress.org
https://wordpress.org/plugins/photoblocks-grid-gallery wpvulndb.com
https://wpvulndb.com/vulnerabilities/9443