Record summary

CVE-2023-29439 has a selected CVSS score of 7.1 (high); EIP currently links 1 repository PoC and 1 Nuclei template.

Description

Unauth. Reflected Cross-Site Scripting (XSS) vulnerability in FooPlugins FooGallery plugin <= 2.2.35 versions.

Description source: CVE List

Exploitation context

Available material

Repository PoCs
1
Nuclei templates
1

CISA SSVC decision

ExploitationNone
AutomatableNo
Technical impactPartial

CISA Coordinator · SSVC 2.0.3 · Evaluated Jan 9, 2025 · Source: CVE List

Affected products and versions

1
ProductSourceVersion rangeStatus

Default status: unaffected

CVE ListThrough 2.2.35affected

Proofs of concept

1

Repository PoCs

GitHubLOURC0D3/CVE-2023-29439Repository PoCby LOURC0D3Stars: 1Not analyzed1 file

647 B

GitHub

PoC details

Nuclei templates

1
ProjectDiscoveryMEDIUMFooGallery plugin <= 2.2.35 - Cross-Site ScriptingCVSS 6.1

Reflected Cross-Site Scripting (XSS) vulnerability in FooPlugins FooGallery plugin <= 2.2.35 versions.

Impact

Authenticated attackers can inject malicious JavaScript code through the post parameter, potentially stealing admin session tokens or performing unauthorized actions as administrators.

Remediation

Upgrade to FooGallery version 2.2.36 or later.

WeaknessesCWE-79
Authorstheamanrawat
Template tagscvecve2023xsswordpresswp-pluginwpfoogalleryauthenticatedfoopluginsvuln
CVSS vector: CVSS:3.1/AV:N/AC:L/PR:N/UI:R/S:C/C:L/I:L/A:N
CPE: cpe:2.3:a:fooplugins:foogallery:*:*:*:*:*:wordpress:*:*
Shodan: http.html:/wp-content/plugins/foogallery/
FOFA: body=/wp-content/plugins/foogallery/

Source: ProjectDiscovery

References

3