CVE-2024-5343
Photo Gallery, Images, Slider in Rbs Image Gallery <= 3.2.19 - Cross-Site Request Forgery to Post Creation and Limited Data Loss
Severity Score
Exploit Likelihood
Affected Versions
Public Exploits
0Exploited in Wild
-Decision
Descriptions
The Photo Gallery, Images, Slider in Rbs Image Gallery plugin for WordPress is vulnerable to Cross-Site Request Forgery in all versions up to, and including, 3.2.19. This is due to missing or incorrect nonce validation on the 'rbs_ajax_create_article' and 'rbs_ajax_reset_views' functions. This makes it possible for unauthenticated attackers to create new posts and reset gallery view counts via a forged request granted they can trick a Contributor+ level user into performing an action such as clicking on a link.
El complemento Photo Gallery, Images, Slider in Rbs Image Gallery para WordPress es vulnerable a Cross-Site Request Forgery en todas las versiones hasta la 3.2.19 incluida. Esto se debe a una validación nonce faltante o incorrecta en las funciones 'rbs_ajax_create_article' y 'rbs_ajax_reset_views'. Esto hace posible que atacantes no autenticados creen nuevas publicaciones y restablezcan el recuento de vistas de la galería a través de una solicitud falsificada, siempre que puedan engañar a un usuario de nivel Contributor+ para que realice una acción como hacer clic en un enlace.
CVSS Scores
SSVC
- Decision:Track*
Timeline
- 2024-05-24 CVE Reserved
- 2024-06-18 CVE Published
- 2024-06-19 EPSS Updated
- 2024-08-01 CVE Updated
- ---------- Exploited in Wild
- ---------- KEV Due Date
- ---------- First Exploit
CWE
- CWE-352: Cross-Site Request Forgery (CSRF)
CAPEC
References (5)
URL | Date | SRC |
---|
URL | Date | SRC |
---|
URL | Date | SRC |
---|
Affected Vendors, Products, and Versions
Vendor | Product | Version | Other | Status | ||||||
---|---|---|---|---|---|---|---|---|---|---|
Vendor | Product | Version | Other | Status | <-- --> | Vendor | Product | Version | Other | Status |
Robosoft Search vendor "Robosoft" | Photo Gallery, Images, Slider In Rbs Image Gallery Search vendor "Robosoft" for product "Photo Gallery, Images, Slider In Rbs Image Gallery" | <= 3.2.19 Search vendor "Robosoft" for product "Photo Gallery, Images, Slider In Rbs Image Gallery" and version " <= 3.2.19" | en |
Affected
|