RSS   Vulnerabilities for 'All-in-one video gallery'   RSS

2021-12-13
 
CVE-2021-24970

CWE-22
 

 
The All-in-One Video Gallery WordPress plugin before 2.5.0 does not sanitise and validate the tab parameter before using it in a require statement in the admin dashboard, leading to a Local File Inclusion issue

 


Copyright 2024, cxsecurity.com

 

Back to Top