PT-2026-30243 · Piwigo · Piwigo
CVSS v3.1
7.2
High
| Vector | AV:N/AC:L/PR:H/UI:N/S:U/C:H/I:H/A:H |
Name of the Vulnerable Software and Affected Versions
Piwigo versions prior to 16.3.0
Description
An issue exists in the
pwg.users.getList Web Service API method where the filter parameter is directly concatenated into a SQL query without proper sanitization. This allows authenticated administrators to execute arbitrary SQL commands via SQL Injection, a technique used to interfere with the queries that an application makes to its database.Recommendations
Update to version 16.3.0.
Avoid using the
filter parameter in the pwg.users.getList API method until the update is applied.Exploit
Fix
SQL injection
Found an issue in the description? Have something to add? Feel free to write us 👾
Weakness Enumeration
Related Identifiers
Affected Products
Piwigo