PT-2026-28100 · Piwigo · Piwigo

Q1Uf3Ng

·

Publicado

2026-03-25

·

Atualizado

2026-04-03

·

CVE-2026-27634

CVSS v3.1

9.8

Crítica

VetorAV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H
Piwigo is an open source photo gallery application for the web. Prior to version 16.3.0, the four date filter parameters (f min date available, f max date available, f min date created, f max date created) in ws std image sql filter() are concatenated directly into SQL without any escaping or type validation. This could result in an unauthenticated attacker reading the full database, including user password hashes. This issue has been patched in version 16.3.0.

Correção

SQL injection

Encontrou algum problema na descrição? Tem algo a acrescentar? Fique à vontade para nos escrever 👾

Enumeração de Fraquezas

Identificadores relacionados

CVE-2026-27634

Produtos afetados

Piwigo