PT-2023-25873 · Piwigo · Piwigo
Scgajge12
·
Published
2023-07-07
·
Updated
2023-07-14
·
CVE-2023-37270
CVSS v3.1
7.6
High
| Vector | AV:N/AC:L/PR:L/UI:N/S:U/C:H/I:L/A:L |
Name of the Vulnerable Software and Affected Versions
Piwigo versions prior to 13.8.0
Description
Piwigo is open source photo gallery software. There is a SQL Injection vulnerability in the login of the administrator screen. The SQL statement that acquires the HTTP Header
User-Agent is vulnerable at the endpoint that records user information when logging in to the administrator screen. It is possible to execute arbitrary SQL statements. Someone who wants to exploit the vulnerability must be logged in to the administrator screen, even with low privileges. Any SQL statement can be executed, which may leak information from the database.Recommendations
For versions prior to 13.8.0, update to version 13.8.0 to resolve the issue.
As a temporary workaround, consider escaping the parameter contents appropriately for those who want to execute a SQL statement verbatim with user-enterable parameters.
Exploit
Fix
SQL injection
Found an issue in the description? Have something to add? Feel free to write us 👾
Weakness Enumeration
Related Identifiers
Affected Products
Piwigo