Forums

[Plugin: NextGEN Gallery] fell security ? (6 posts)

  1. Pense Libre
    Member
    Posted 3 years ago #

    french forum give a signal fell security in this plugin
    may you say me the reality about that ?

    http://wordpress.org/extend/plugins/nextgen-gallery/

  2. bee dudler
    Member
    Posted 3 years ago #

    Hi,
    may you kindly post a link to that Forum thread?
    best regards
    bee

  3. Pense Libre
    Member
    Posted 3 years ago #

  4. Commeuneimage
    Member
    Posted 3 years ago #

  5. bee dudler
    Member
    Posted 3 years ago #

    Hi,
    this already has been discussed on Alex page (which is currently offline -moving) and its a question wether to define this as a security problem, hence you have to be logged in as admin as he told to the wp backend. If you are you can do everything you like anyway putting malicious code anywhere. So to me it seems not to be a security issue.

    best regards
    bee

  6. Alex Rabe
    Member
    Posted 3 years ago #

    A author/editor/admin which has the rights/capabilities to edit galleries can enter any malicious script code inside the description field of a picture.

    So if you grant people access to your blog , which you can't trust it's better not to use NextGEN gallery. For me this is not a security problem, because the same can happend at any post/page... And nobody claim this as an XSS.

    I'm open for any criticism in this point

Topic Closed

This topic has been closed to new replies.

About this Topic

Tags

No tags yet.