CVE-2015-1784
Last modified
CVE-2015-1784 is a high-severity vulnerability rated 8.8/10 on the CVSS scale. In nextgen-galery wordpress plugin before 2.0.77.3 there are two vulnerabilities which can allow an attacker to gain full access over the web application. The vulnerabilities lie in how the application validates user uploaded files and lack of security measures preventing unwanted HTTP requests.. EPSS estimates a 1.55% chance of exploitation in the next 30 days.
Description
In nextgen-galery wordpress plugin before 2.0.77.3 there are two vulnerabilities which can allow an attacker to gain full access over the web application. The vulnerabilities lie in how the application validates user uploaded files and lack of security measures preventing unwanted HTTP requests.
Metrics
CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H
Weakness Enumeration
Affected Software
| Vendor | Product | Versions |
|---|---|---|
| Imagely | Nextgen Gallery | < 2.0.77.3 |
References
- https://blog.nettitude.com/uk/crsf-and-unsafe-arbitrary-file-upload-in-nextgen-gallery-plugin-for-wordpressExploit, Third Party Advisory
- https://wpscan.com/vulnerability/c894727a-b779-4583-a860-13c2c27275d4Third Party Advisory
- https://blog.nettitude.com/uk/crsf-and-unsafe-arbitrary-file-upload-in-nextgen-gallery-plugin-for-wordpressExploit, Third Party Advisory
- https://wpscan.com/vulnerability/c894727a-b779-4583-a860-13c2c27275d4Third Party Advisory
Timeline
- Published
- Last Modified
- Status
- Modified
Frequently Asked Questions
What is CVE-2015-1784?
How severe is CVE-2015-1784?
How do I fix CVE-2015-1784?
How Strix Helps
- How Strix found a critical auth bypass in etcdStrix autonomously discovered a critical authentication bypass in etcd, later designated CVE-2026-33413.
- Autonomous PentestingAI agents that find and validate exploitable vulnerabilities like this one across your applications.
- PR ReviewsPentest every pull request so vulnerable code is caught before it ships to production.
- AI Penetration TestingHow AI-driven penetration testing continuously covers your attack surface.
Related CVEs from 2015
- CVE-2015-1778The custom authentication realm used by karaf-tomcat's "open…
- CVE-2015-1779The VNC websocket frame decoder in QEMU allows remote attack…8.6
- CVE-2015-1780oVirt users with MANIPULATE_STORAGE_DOMAIN permissions can a…6.5
- CVE-2015-1781Buffer overflow in the gethostbyname_r and other unspecified…
- CVE-2015-1782The kex_agree_methods function in libssh2 before 1.5.0 allow…
- CVE-2015-1783The prefix variable in the get_or_define_ns function in Lass…
- CVE-2015-1785In nextgen-galery wordpress plugin before 2.0.77.3 there are…6.5
- CVE-2015-1786Cross-site request forgery (CSRF) vulnerability in Zend/Vali…
- CVE-2015-1787The ssl3_get_client_key_exchange function in s3_srvr.c in Op…
- CVE-2015-1788The BN_GF2m_mod_inv function in crypto/bn/bn_gf2m.c in OpenS…
- CVE-2015-1789The X509_cmp_time function in crypto/x509/x509_vfy.c in Open…
- CVE-2015-1790The PKCS7_dataDecodefunction in crypto/pkcs7/pk7_doit.c in O…
Are you affected by CVE-2015-1784?
Run a free Strix scan to check your systems for this vulnerability.
Scan your code nowSource: NVD / NIST
