PT-2023-25873 · Piwigo · Piwigo

Scgajge12

·

Publicado

2023-07-07

·

Atualizado

2023-07-14

·

CVE-2023-37270

CVSS v3.1

7.6

Alta

VetorAV:N/AC:L/PR:L/UI:N/S:U/C:H/I:L/A:L
Name of the Vulnerable Software and Affected Versions Piwigo versions prior to 13.8.0
Description Piwigo is open source photo gallery software. There is a SQL Injection vulnerability in the login of the administrator screen. The SQL statement that acquires the HTTP Header User-Agent is vulnerable at the endpoint that records user information when logging in to the administrator screen. It is possible to execute arbitrary SQL statements. Someone who wants to exploit the vulnerability must be logged in to the administrator screen, even with low privileges. Any SQL statement can be executed, which may leak information from the database.
Recommendations For versions prior to 13.8.0, update to version 13.8.0 to resolve the issue. As a temporary workaround, consider escaping the parameter contents appropriately for those who want to execute a SQL statement verbatim with user-enterable parameters.

Exploit

Correção

SQL injection

Encontrou algum problema na descrição? Tem algo a acrescentar? Fique à vontade para nos escrever 👾

Enumeração de Fraquezas

Identificadores relacionados

CVE-2023-37270
GHSA-934W-QJ9P-3QCX

Produtos afetados

Piwigo