PT-2017-12815 · Wd · Photo Gallery By Wd
Publicado
2017-08-21
·
Atualizado
2019-07-08
·
CVE-2017-12977
CVSS v3.1
7.2
Alta
| Vetor | AV:N/AC:L/PR:H/UI:N/S:U/C:H/I:H/A:H |
Name of the Vulnerable Software and Affected Versions
Photo Gallery by WD - Responsive Photo Gallery versions prior to 1.3.51
Description
The issue is related to a SQL injection vulnerability. It is associated with the
bwg edit tag() function in photo-gallery.php and the edit tag() function in admin/controllers/BWGControllerTags bwg.php. The vulnerability can be exploited through the tag id parameter and is accessible to administrators.Recommendations
For versions prior to 1.3.51, update to version 1.3.51 or later to resolve the issue. As a temporary workaround, consider restricting access to the
tag id parameter in the affected API endpoints until a patch is available.Correção
SQL injection
Encontrou algum problema na descrição? Tem algo a acrescentar? Fique à vontade para nos escrever 👾
Enumeração de Fraquezas
Identificadores relacionados
Produtos afetados
Photo Gallery By Wd