CVE-2023-44244
CVSS 3.1 Score 6.1 of 10 (medium)
Details
Published Oct 2, 2023
Updated: Oct 4, 2023
CWE ID 79
Summary
CVE-2023-44244 is a newly disclosed Cross-Site Scripting (XSS) vulnerability affecting versions 2.2.44 and below of the FooGallery plugin by FooPlugins. An attacker can exploit this unauthenticated reflected XSS flaw to inject malicious scripts into a victim's web browser, potentially leading to session hijacking, data theft, or other malicious activities. This vulnerability poses a significant risk to websites utilizing the affected plugin and calls for immediate patching to mitigate the threat.
Prevent cyber attacks with Recorded Future by prioritizing and patching critical vulnerabilities being exploited by threat actors targeting your industry. Book your demo to learn more.
Share