FlatPress Media Manager Plugin panel.mediamanager.file.php main cross site scripting
Published Dec 27, 2022
6.1
MEDIUMCVSS 3.1
EPSS 0.52%
Description
A vulnerability was found in FlatPress and classified as problematic. This issue affects the function main of the file fp-plugins/mediamanager/panels/panel.mediamanager.file.php of the component Media Manager Plugin. The manipulation of the argument mm-newgallery-name leads to cross site scripting. The attack may be initiated remotely. The name of the patch is d3f329496536dc99f9707f2f295d571d65a496f5. It is recommended to apply a patch to fix this issue. The identifier VDB-216869 was assigned to this vulnerability.
Affected products
- Vendor n/a Product FlatPress Defaultn/a
Default status is the baseline for the product, each version can override it (e.g. patched versions marked unaffected).
| Vendor | Product | Default status | Versions | |||
|---|---|---|---|---|---|---|
| n/a | FlatPress | n/a |
|
No data.
No Red Hat product state for this CVE.
No package ranges for this CVE.
Remediation
No remediation recorded yet.
References (4)
- https://github.com/flatpressblog/flatpress/commit/d3f329496536dc99f9707f2f295d571d65a496f5 patchThird Party Advisory
- https://github.com/flatpressblog/flatpress/issues/177 issue-trackingIssue TrackingPatchThird Party Advisory
- https://vuldb.com/?ctiid.216869 signaturepermissions-requiredThird Party Advisory
- https://vuldb.com/?id.216869 vdb-entrytechnical-descriptionThird Party Advisory
| Link | Providers | Tags |
|---|---|---|
| https://github.com/flatpressblog/flatpress/commit/d3f329496536dc99f9707f2f295d571d65a496f5 | patchThird Party Advisory | |
| https://github.com/flatpressblog/flatpress/issues/177 | issue-trackingIssue TrackingPatchThird Party Advisory | |
| https://vuldb.com/?ctiid.216869 | signaturepermissions-requiredThird Party Advisory | |
| https://vuldb.com/?id.216869 | vdb-entrytechnical-descriptionThird Party Advisory |
Change history (0)
No recorded changes yet.