CVE-2023-29439
HIGHNuclei
WordPress FooGallery Plugin <= 2.2.35 is vulnerable to Cross Site Scripting (XSS)
Record summary
CVE-2023-29439 has a selected CVSS score of 7.1 (high); EIP currently links 1 repository PoC and 1 Nuclei template.
Description
Unauth. Reflected Cross-Site Scripting (XSS) vulnerability in FooPlugins FooGallery plugin <= 2.2.35 versions.
Description source: CVE List
Exploitation context
Affected products and versions
1| Product | Source | Version range | Status |
|---|---|---|---|
FooGalleryBrowse FooPlugins / FooGalleryDefault status: unaffected | CVE List | Through 2.2.35 | affected |
Proofs of concept
1Repository PoCs
GitHubLOURC0D3/CVE-2023-29439Repository PoCby LOURC0D3Stars: 1Not analyzed1 file
Nuclei templates
1ProjectDiscoveryMEDIUMFooGallery plugin <= 2.2.35 - Cross-Site ScriptingCVSS 6.1
Reflected Cross-Site Scripting (XSS) vulnerability in FooPlugins FooGallery plugin <= 2.2.35 versions.
Impact
Authenticated attackers can inject malicious JavaScript code through the post parameter, potentially stealing admin session tokens or performing unauthorized actions as administrators.
Remediation
Upgrade to FooGallery version 2.2.36 or later.
WeaknessesCWE-79
Authorstheamanrawat
Template tagscvecve2023xsswordpresswp-pluginwpfoogalleryauthenticatedfoopluginsvuln
CVSS vector: CVSS:3.1/AV:N/AC:L/PR:N/UI:R/S:C/C:L/I:L/A:N
CPE: cpe:2.3:a:fooplugins:foogallery:*:*:*:*:*:wordpress:*:*
Shodan: http.html:/wp-content/plugins/foogallery/
FOFA: body=/wp-content/plugins/foogallery/
https://lourcode.kr/posts/CVE-2023-29439-Analysis?_s_id=cve https://wordpress.org/plugins/foogallery/ https://nvd.nist.gov/vuln/detail/CVE-2023-29439 https://patchstack.com/database/vulnerability/foogallery/wordpress-foogallery-plugin-2-2-35-reflected-cross-site-scripting-xss-vulnerability?_s_id=cve https://github.com/ARPSyndicate/cvemon
Source: ProjectDiscovery
References
3lourcode.krTechnical description
https://lourcode.kr/posts/CVE-2023-29439-Analysis?_s_id=cve nvd.nist.gov
https://nvd.nist.gov/vuln/detail/CVE-2023-29439 patchstack.comvdb entry
https://patchstack.com/database/vulnerability/foogallery/wordpress-foogallery-plugin-2-2-35-reflected-cross-site-scripting-xss-vulnerability?_s_id=cve