vendor:
Premium Gallery Manager
by:
Hannaichi
7,5
CVSS
HIGH
Unauthenticated Configuration Access
N/A
CWE
Product Name: Premium Gallery Manager
Affected Version From: N/A
Affected Version To: N/A
Patch Exists: YES
Related CWE: N/A
CPE: N/A
Metasploit:
N/A
Other Scripts:
N/A
Tags: N/A
CVSS Metrics: N/A
Nuclei References:
N/A
Nuclei Metadata: N/A
Platforms Tested: Windows 7 32-bit | Google Chrome
2014
WordPress Plugins Premium Gallery Manager Unauthenticated Configuration Access Vulnerability
A vulnerability in the Wordpress Plugins Premium Gallery Manager allows an unauthenticated user to access the configuration of the plugin. This can be exploited by sending a POST request to the ajax.php file with the action set to 'save' and the values set to the desired configuration. This can be used to set the admin email, allow users to register, and set the default role to administrator.
Mitigation:
Ensure that the Wordpress Plugins Premium Gallery Manager is up to date and that all users are authenticated before accessing the configuration.