Vulnerabilities > CVE-2021-24293 - Unspecified vulnerability in Imagely Nextgen Gallery
Attack vector
NETWORK Attack complexity
LOW Privileges required
NONE Confidentiality impact
LOW Integrity impact
LOW Availability impact
NONE Summary
In the eCommerce module of the NextGEN Gallery Pro WordPress plugin before 3.1.11, there is an action to call get_cart_items via photocrati_ajax , after that the settings[shipping_address][name] is able to inject malicious javascript.
Vulnerable Configurations
Part | Description | Count |
---|---|---|
Application | 1 |