The All-in-One Video Gallery WordPress plugin before 2.5...
High severity
Unreviewed
Published
Dec 14, 2021
to the GitHub Advisory Database
•
Updated Feb 1, 2023
Description
Published by the National Vulnerability Database
Dec 13, 2021
Published to the GitHub Advisory Database
Dec 14, 2021
Last updated
Feb 1, 2023
The All-in-One Video Gallery WordPress plugin before 2.5.0 does not sanitise and validate the tab parameter before using it in a require statement in the admin dashboard, leading to a Local File Inclusion issue
References