← back
CVE-2011-4624

CVE-2011-4624

18Vexday Risk Score

Patch soon. It has a working public exploit.

ssvc Attendepss 7.1%
exploitation probability
7.1%top 6% of all CVEs
observed exploitation
nono source reports it
Cross-site scripting (XSS) vulnerability in facebook.php in the GRAND FlAGallery plugin (flash-album-gallery) before 1.57 for WordPress allows remote attackers to inject arbitrary web script or HTML via the i parameter.
Affected products
n/a · n/a