漏洞信息
尽管我们使用了先进的大模型技术,但其输出仍可能包含不准确或过时的信息。神龙努力确保数据的准确性,但请您根据实际情况进行核实和判断。
Vulnerability Title
Photo Gallery < 1.5.75 - Stored Cross-Site Scripting via Uploaded SVG
Vulnerability Description
The Photo Gallery by 10Web – Mobile-Friendly Image Gallery WordPress plugin before 1.5.75 did not ensure that uploaded SVG files added to a gallery do not contain malicious content. As a result, users allowed to add images to gallery can upload an SVG file containing JavaScript code, which will be executed when accessing the image directly (ie in the /wp-content/uploads/photo-gallery/ folder), leading to a Cross-Site Scripting (XSS) issue
CVSS Information
N/A
Vulnerability Type
在Web页面生成时对输入的转义处理不恰当(跨站脚本)
Vulnerability Title
WordPress 插件跨站脚本漏洞
Vulnerability Description
WordPress是Wordpress基金会的一套使用PHP语言开发的博客平台。该平台支持在PHP和MySQL的服务器上架设个人博客网站。WordPress 插件是WordPress开源的一个应用插件。 10Web – Mobile-Friendly Image Gallery WordPress 插件 1.5.75之前版本存在跨站脚本漏洞,该漏洞允许向图库添加图像的用户上传包含JavaScript代码的SVG文件,该文件将在直接访问图像时执行,从而导致跨站点脚本(XSS)问题。
CVSS Information
N/A
Vulnerability Type
N/A