Home
Trends
Vulnerabilities
News
Researchers
Why dbugs?

Harry Goodman

Researcher fromNCC Group
#15685of 53,632
17.3Total CVSS
Vulnerabilities · 2
High
1
Critical
1
PT-2021-19808
9.8
2021-05-13
Piwigo · Piwigo · CVE-2021-32615
**Name of the Vulnerable Software and Affected Versions** Piwigo version 11.4.0 **Description** The issue allows for SQL Injection through the `order[0][dir]` parameter in the `admin/user list backend.php` endpoint. **Recommendations** For Piwigo version 11.4.0, as a temporary workaround, consider restricting access to the `admin/user list backend.php` endpoint until a patch is available. Avoid using the `order[0][dir]` parameter in this endpoint to minimize the risk of exploitation. At the moment, there is no information about a newer version that contains a fix for this vulnerability.
PT-2021-19504
7.5
2021-04-26
Piwigo · Piwigo Localfileseditor · CVE-2021-31783
**Name of the Vulnerable Software and Affected Versions** Piwigo LocalFilesEditor extension versions prior to 11.4.0.1 **Description** The issue allows for Local File Inclusion due to the lack of proper validation of the `file` parameter in the `show default.php` file. **Recommendations** For versions prior to 11.4.0.1, update to version 11.4.0.1 or later to resolve the issue.