CVE-2014-125096
Published on: Not Yet Published
Last Modified on: 04/13/2023 07:51:00 PM UTC
Certain versions of Fancy Gallery from Fancy Gallery Project contain the following vulnerability:
A vulnerability was found in Fancy Gallery Plugin 1.5.12. It has been declared as problematic. Affected by this vulnerability is an unknown functionality of the file class.options.php of the component Options Page. The manipulation leads to cross site scripting. The attack can be launched remotely. Upgrading to version 1.5.13 is able to address this issue. The name of the patch is fdf1f9e5a1ec738900f962e69c6fa4ec6055ed8d. It is recommended to upgrade the affected component. The identifier VDB-225349 was assigned to this vulnerability.
- CVE-2014-125096 has been assigned by
[email protected] to track the vulnerability - currently rated as MEDIUM severity.
CVSS3 Score: 6.1 - MEDIUM
Attack Vector ⓘ |
Attack Complexity |
Privileges Required |
User Interaction |
---|---|---|---|
NETWORK | LOW | NONE | REQUIRED |
Scope | Confidentiality Impact |
Integrity Impact |
Availability Impact |
CHANGED | LOW | LOW | NONE |
CVE References
Description | Tags ⓘ | Link |
---|---|---|
CVE-2014-125096 | Fancy Gallery Plugin Options Page class.options.php cross site scripting | Permissions Required Third Party Advisory web.archive.org text/html Inactive LinkNot Archived |
![]() |
Fixed: XSS issue in the options page, Improved: Options page slug is … · wp-plugins/fancy-gallery@fdf1f9e · GitHub | Patch github.com text/html |
![]() |
Login required | Permissions Required Third Party Advisory vuldb.com text/html Inactive LinkNot Archived |
![]() |
There are currently no QIDs associated with this CVE
Known Affected Configurations (CPE V2.3)
Type | Vendor | Product | Version | Update | Edition | Language |
---|---|---|---|---|---|---|
Application | Fancy Gallery Project | Fancy Gallery | All | All | All | All |
- cpe:2.3:a:fancy_gallery_project:fancy_gallery:*:*:*:*:*:wordpress:*:*:
No vendor comments have been submitted for this CVE