Back to search
CVE-2022-0186
Published: Feb 21, 2022
Modified: Aug 2, 2024
PUBLISHED
Description
The Image Photo Gallery Final Tiles Grid WordPress plugin before 3.5.3 does not sanitise and escape the Description field when editing a gallery, allowing users with a role as low as contributor to perform Cross-Site Scripting attacks against other users having access to the gallery dashboard
| Vendor | Product | Versions |
|---|---|---|
Unknown | Image Photo Gallery Final Tiles Grid | affected 3.5.3 - < 3.5.3 |
Weaknesses (CWE)
References
Security Training
Train your team to recognize and prevent security threats with our comprehensive security awareness program.
Start TrainingVulnerability Scanning
Discover vulnerabilities in your applications and infrastructure before attackers do.
Scan Now