PT-2023-25873 · Piwigo · Piwigo
Scgajge12
·
Publicado
2023-07-07
·
Atualizado
2023-07-14
·
CVE-2023-37270
CVSS v3.1
7.6
Alta
| Vetor | AV:N/AC:L/PR:L/UI:N/S:U/C:H/I:L/A:L |
Name of the Vulnerable Software and Affected Versions
Piwigo versions prior to 13.8.0
Description
Piwigo is open source photo gallery software. There is a SQL Injection vulnerability in the login of the administrator screen. The SQL statement that acquires the HTTP Header
User-Agent is vulnerable at the endpoint that records user information when logging in to the administrator screen. It is possible to execute arbitrary SQL statements. Someone who wants to exploit the vulnerability must be logged in to the administrator screen, even with low privileges. Any SQL statement can be executed, which may leak information from the database.Recommendations
For versions prior to 13.8.0, update to version 13.8.0 to resolve the issue.
As a temporary workaround, consider escaping the parameter contents appropriately for those who want to execute a SQL statement verbatim with user-enterable parameters.
Exploit
Correção
SQL injection
Encontrou algum problema na descrição? Tem algo a acrescentar? Fique à vontade para nos escrever 👾
Enumeração de Fraquezas
Identificadores relacionados
Produtos afetados
Piwigo