ShadowTrackr

Search the CVE vulnerability database

Look up vulnerabilities by software, product or CVE number.

1 result for “CVE-2020-35943”

CVEPublishedCVSSShadowTrackr CVSSSummary
CVE:
CVE-2020-35943
Published
2021-02-09
CVSS:
6.5
ShadowTrackr CVSS:
5.0
Summary:
A Cross-Site Request Forgery (CSRF) issue in the NextGEN Gallery plugin before 3.5.0 for WordPress allows File Upload. (It is possible to bypass CSRF protection by simply not including a nonce parameter.)