PT-2023-10123 · Piwigo · Piwigo-Guest-Book
CVE-2014-125053
·
Publicado
2023-01-06
·
Atualizado
2024-05-17
CVSS v2.0
5.2
Média
| Vetor | AV:A/AC:L/Au:S/C:P/I:P/A:P |
Name of the Vulnerable Software and Affected Versions
Piwigo-Guest-Book versions up to 1.3.0
Description
A critical issue affects the Navigation Bar component, specifically the include/guestbook.inc.php file. The manipulation of the
start argument leads to sql injection.Recommendations
For versions up to 1.3.0, upgrade to version 1.3.1 to address this issue. As a temporary workaround, consider restricting access to the vulnerable component until the upgrade is applied.
Correção
SQL injection
Encontrou algum problema na descrição? Tem algo a acrescentar? Fique à vontade para nos escrever 👾
Enumeração de Fraquezas
Identificadores relacionados
Produtos afetados
Piwigo-Guest-Book