cve/2021/CVE-2021-25041.md

18 lines
844 B
Markdown
Raw Normal View History

2024-05-25 21:48:12 +02:00
### [CVE-2021-25041](https://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2021-25041)
![](https://img.shields.io/static/v1?label=Product&message=Photo%20Gallery%20by%2010Web%20%E2%80%93%20Mobile-Friendly%20Image%20Gallery&color=blue)
![](https://img.shields.io/static/v1?label=Version&message=1.5.68%3C%201.5.68%20&color=brighgreen)
![](https://img.shields.io/static/v1?label=Vulnerability&message=CWE-79%20Cross-site%20Scripting%20(XSS)&color=brighgreen)
### Description
The Photo Gallery by 10Web WordPress plugin before 1.5.68 is vulnerable to Reflected Cross-Site Scripting (XSS) issues via the bwg_album_breadcrumb_0 and shortcode_id GET parameters passed to the bwg_frontend_data AJAX action
### POC
#### Reference
- https://wpscan.com/vulnerability/32aee3ea-e0af-44da-a16c-102c83eaed8f
#### Github
No PoCs found on GitHub currently.