vendor:
All-in-One Video Gallery plugin
by:
Mohamed Magdy Abumusilm Aka m19o
7.5
CVSS
HIGH
Local File Inclusion (LFI)
98
CWE
Product Name: All-in-One Video Gallery plugin
Affected Version From: 2.4.2009
Affected Version To: 2.4.2009
Patch Exists: NO
Related CWE:
CPE:
Platforms Tested: Windows, Linux
2020
WordPress Plugin All-in-One Video Gallery plugin 2.4.9 – Local File Inclusion (LFI)
Authenticated user can exploit LFI vulnerability in tab parameter.
Mitigation:
Ensure that user input is properly sanitized and validated before being used in the application.