MEDIUM
Multiple cross-site scripting (XSS) vulnerabilities in the Digital Zoom Studio (DZS) Video Gallery plugin for WordPress allow remote attackers to inject arbitrary web script or HTML via the logoLink parameter to (1) preview.swf, (2) preview_skin_rouge.swf, (3) preview_allchars.swf, or (4) preview_skin_overlay.swf in deploy/
Published May 30, 2014
4.3
MEDIUMCVSS 2.0
EPSS 1.62%
Description
Affected products
Remediation
Metrics
References (2)
Change history (0)
No recorded changes yet.