PT-2023-2929 · Piwigo · Piwigo

Plegall

·

Published

2023-05-17

·

Updated

2025-01-22

·

CVE-2023-27233

CVSS v2.0

9.0

High

VectorAV:N/AC:L/Au:S/C:C/I:C/A:C
Name of the Vulnerable Software and Affected Versions Piwigo versions prior to 13.6.0
Description The issue is related to a lack of validation of XML object sequences in the user list backend.php script of the Piwigo content management system. This can be exploited by a remote attacker to conduct SQL injection attacks via the order[0][dir] parameter at the "user list backend.php" endpoint.
Recommendations For versions prior to 13.6.0, update to version 13.6.0 or later to resolve the issue. As a temporary workaround, consider restricting access to the user list backend.php endpoint or disabling the use of the order[0][dir] parameter until a patch is applied.

Exploit

Fix

SQL injection

Weakness Enumeration

Related Identifiers

BDU:2023-02922
CVE-2023-27233

Affected Products

Piwigo