CVE-2015-1784
Last modified
CVE-2015-1784 is a high-severity vulnerability rated 8.8/10 on the CVSS scale. In nextgen-galery wordpress plugin before 2.0.77.3 there are two vulnerabilities which can allow an attacker to gain full access over the web application. The vulnerabilities lie in how the application validates user uploaded files and lack of security measures preventing unwanted HTTP requests.. EPSS estimates a 1.55% chance of exploitation in the next 30 days.
Description
In nextgen-galery wordpress plugin before 2.0.77.3 there are two vulnerabilities which can allow an attacker to gain full access over the web application. The vulnerabilities lie in how the application validates user uploaded files and lack of security measures preventing unwanted HTTP requests.
Metrics
CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H
Weakness Enumeration
Affected Software
| Vendor | Product | Versions |
|---|---|---|
| Imagely | Nextgen Gallery | < 2.0.77.3 |
References
- https://blog.nettitude.com/uk/crsf-and-unsafe-arbitrary-file-upload-in-nextgen-gallery-plugin-for-wordpressExploit, Third Party Advisory
- https://wpscan.com/vulnerability/c894727a-b779-4583-a860-13c2c27275d4Third Party Advisory
- https://blog.nettitude.com/uk/crsf-and-unsafe-arbitrary-file-upload-in-nextgen-gallery-plugin-for-wordpressExploit, Third Party Advisory
- https://wpscan.com/vulnerability/c894727a-b779-4583-a860-13c2c27275d4Third Party Advisory
Timeline
- Published
- Last Modified
- Status
- Modified
Frequently Asked Questions
What is CVE-2015-1784?
How severe is CVE-2015-1784?
How do I fix CVE-2015-1784?
Are you affected by CVE-2015-1784?
Run a free Strix scan to check your systems for this vulnerability.
Scan your code nowSource: NVD / NIST
