cve/2020/CVE-2020-35581.md
2024-05-25 21:48:12 +02:00

855 B

CVE-2020-35581

Description

A stored cross-site scripting (XSS) issue in Envira Gallery Lite before 1.8.3.3 allows remote attackers to inject arbitrary JavaScript/HTML code via a POST /wp-admin/admin-ajax.php request with the meta[title] parameter.

POC

Reference

Github