PT-2017-12815 · Wd · Photo Gallery By Wd
Published
2017-08-21
·
Updated
2019-07-08
·
CVE-2017-12977
CVSS v3.1
7.2
High
| Vector | AV:N/AC:L/PR:H/UI:N/S:U/C:H/I:H/A:H |
Name of the Vulnerable Software and Affected Versions
Photo Gallery by WD - Responsive Photo Gallery versions prior to 1.3.51
Description
The issue is related to a SQL injection vulnerability. It is associated with the
bwg edit tag() function in photo-gallery.php and the edit tag() function in admin/controllers/BWGControllerTags bwg.php. The vulnerability can be exploited through the tag id parameter and is accessible to administrators.Recommendations
For versions prior to 1.3.51, update to version 1.3.51 or later to resolve the issue. As a temporary workaround, consider restricting access to the
tag id parameter in the affected API endpoints until a patch is available.Fix
SQL injection
Found an issue in the description? Have something to add? Feel free to write us 👾
Weakness Enumeration
Related Identifiers
Affected Products
Photo Gallery By Wd