HackTips.

页面数据均来自于CVE官方,仅调用Api进行查询

1@1042.net

CVE编号CVE-2024-12114
发布日期2025-03-08T05:30:09.469Z
更新日期2025-03-10T16:11:56.871Z
状态PUBLISHED
受影响的供应商bradvin
受影响的产品FooGallery – Responsive Photo Gallery, Image Viewer, Justified, Masonry & Carousel
描述The FooGallery – Responsive Photo Gallery, Image Viewer, Justified, Masonry & Carousel plugin for WordPress is vulnerable to Insecure Direct Object Reference in all versions up to, and including, 2.4.29 via the foogallery_attachment_modal_save AJAX action due to missing validation on a user controlled key (img_id). This makes it possible for authenticated attackers, with granted access and above, to update arbitrary post and page content. This requires the Gallery Creator Role setting to be a value lower than 'Editor' for there to be any real impact.

参考链接:

Image Additional Image