CVE-2013-3261 - CVE House
Back to Database
Status published Medium CVE-2013-3261

Cross-site scripting (XSS) vulnerability in wp-admin/admin.php in the GRAND FlAGallery...

Vulnerability Description

Cross-site scripting (XSS) vulnerability in wp-admin/admin.php in the GRAND FlAGallery plugin before 2.72 for WordPress allows remote attackers to inject arbitrary web script or HTML via the s parameter in a flag-manage-gallery action.

Impact Analysis

Refer to official advisory for detailed impact metrics.

Remediation

Ensure systems are updated to the latest vendor-supplied patch levels.

THREAT MONITOR

Am I Vulnerable?

Launch our assessment wizard to check if your infrastructure is exposed to • CVE-2013-3261

Credits & Attribution

No credits recorded in the NVD database.

Affected Vendor

photogallerycreator

View all reports →

Affected Software

flash-album-gallery
Vulnerable Versions:
0, 0.29, 0.32, 0.33, 0.34, 0.35, 0.36, 0.37, 0.38, 0.39, 0.40, 0.41, 0.42, 0.43, 0.44, 0.45, 0.46, 0.49, 0.50, 0.52, 0.53, 0.54, 0.55, 0.56, 0.57, 0.58, 0.59, 0.60, 0.61, 1.11, 1.12, 1.13, 1.20, 1.21, 1.22, 1.23, 1.31, 1.32, 1.33, 1.40, 1.41, 1.42, 1.43, 1.44, 1.45, 1.47, 1.48, 1.49, 1.50, 1.51, 1.52, 1.53, 1.54, 1.55, 1.56, 1.57, 1.58, 1.59, 1.60, 1.61, 1.62, 1.63, 1.64, 1.65, 1.66, 1.67, 1.70, 1.71, 1.72, 1.73, 1.74, 1.75, 1.76, 1.77, 1.78, 1.79, 1.80, 1.81, 1.82, 1.83, 1.84, 1.85, 1.90, 2.00, 2.10, 2.11, 2.12, 2.14, 2.15, 2.16, 2.17, 2.18, 2.50, 2.51, 2.52, 2.53, 2.54, 2.55, 2.56, 2.70

Timeline

Official Publish: June 1st, 2013
Last Modified: September 16th, 2024
Added to House: July 19th, 2026

CVSS Vectors

Weaknesses (CWE)

No CWE data available

MITRE ATT&CK TTPs

No associated TTPs found for this vulnerability.