PT-2023-25873 · Piwigo · Piwigo

Scgajge12

·

Published

2023-07-07

·

Updated

2023-07-14

·

CVE-2023-37270

CVSS v3.1

7.6

High

VectorAV:N/AC:L/PR:L/UI:N/S:U/C:H/I:L/A:L
Name of the Vulnerable Software and Affected Versions Piwigo versions prior to 13.8.0
Description Piwigo is open source photo gallery software. There is a SQL Injection vulnerability in the login of the administrator screen. The SQL statement that acquires the HTTP Header User-Agent is vulnerable at the endpoint that records user information when logging in to the administrator screen. It is possible to execute arbitrary SQL statements. Someone who wants to exploit the vulnerability must be logged in to the administrator screen, even with low privileges. Any SQL statement can be executed, which may leak information from the database.
Recommendations For versions prior to 13.8.0, update to version 13.8.0 to resolve the issue. As a temporary workaround, consider escaping the parameter contents appropriately for those who want to execute a SQL statement verbatim with user-enterable parameters.

Exploit

Fix

SQL injection

Found an issue in the description? Have something to add? Feel free to write us 👾

Weakness Enumeration

Related Identifiers

CVE-2023-37270
GHSA-934W-QJ9P-3QCX

Affected Products

Piwigo