Vector: | Remote |
Severity: | Medium |
Patch: | Patched |
Impact: | Data Manipulation |
Software: | Piwigo 2.x , vulnerable versions: <2.5.6, 2.6.5, and 2.7.3 |
SQL inection vulnerability has been discovered in Piwigo.
Vulnerability is caused by an unspecified input validation error. A remote attacker can send a specially crafted request to the vulnerable application and execute arbitrary SQL commands in application`s database.
Further exploitation of this vulnerability may result in unauthorized data manipulation.
Solution:
For Piwigo 2.x: Update to version 2.5.6, 2.6.5, or 2.7.3.
Links:
- http://piwigo.org/forum/viewtopic.php
- http://piwigo.org/releases/2.5.6
- http://piwigo.org/releases/2.6.5
- http://piwigo.org/releases/2.7.3