PT-2026-30248 · Piwigo · Piwigo
CVSS v3.1
7.2
High
| Vector | AV:N/AC:L/PR:H/UI:N/S:U/C:H/I:H/A:H |
Name of the Vulnerable Software and Affected Versions
Piwigo versions prior to 16.3.0
Description
An issue exists in the Activity List API endpoint that allows an authenticated administrator to perform a SQL Injection. This technique involves inserting malicious SQL code into a query to manipulate the database, enabling the extraction of sensitive information such as user credentials, email addresses, and all stored content.
Recommendations
Update to version 16.3.0.
Exploit
Fix
SQL injection
Found an issue in the description? Have something to add? Feel free to write us 👾
Weakness Enumeration
Related Identifiers
Affected Products
Piwigo