CVE-2022-1394
Summary
| CVE | CVE-2022-1394 |
| State | PUBLIC |
| Assigner | [email protected] |
| Source Priority | CVE Program / NVD first with legacy fallback |
| Published | 2022-06-08 10:15:00 UTC |
| Updated | 2022-06-17 00:58:00 UTC |
| Description | The Photo Gallery by 10Web WordPress plugin before 1.6.4 does not properly validate and escape some of its settings, which could allow high privilege users such as admin to perform Cross-Site Scripting attacks when unfiltered_html is disallowed |
NVD Known Affected Configurations (CPE 2.3)
| Type | Vendor | Product | Version | Update | Edition | Language |
|---|
| Application |
10web |
Photo Gallery |
All |
All |
All |
All |
References
| Reference | Source | Link | Tags |
|---|
| Attention Required! | Cloudflare |
MISC |
wpscan.com |
|
| CVE Program record |
CVE.ORG |
www.cve.org |
canonical |
| NVD vulnerability detail |
NVD |
nvd.nist.gov |
canonical, analysis |
Vendor Comments And Credit
Discovery Credit
LEGACY: 0ppr2s
Legacy QID Mappings
- 150549 WordPress Photo Gallery Plugin: Stored Cross-Site Scripting Vulnerability (CVE-2022-1394)