CVE-2015-1517: SQL Injection
Published Feb 20, 2015
·Updated
SQL injection vulnerability in Piwigo before 2.7.4, when all filters are activated, allows remote authenticated users to execute arbitrary SQL commands via the filterlevel parameter in a "Refresh photo set" action in the batchmanager page to admin.php.
Affected Software
1 affected component
Piwigo piwigo<=2.7.3
Remediation
Patch Available
Event History
Feb 20, 2015
CVE Published
via MITRE·04:00 PM
Data Sourced
via MITRE·04:00 PM
Description
Frequently Asked Questions
1
What is the severity of CVE-2015-1517?
CVE-2015-1517 is considered a medium severity vulnerability due to its potential for SQL injection by authenticated users.
2
How do I fix CVE-2015-1517?
To fix CVE-2015-1517, upgrade Piwigo to version 2.7.4 or later.
3
Who is affected by CVE-2015-1517?
CVE-2015-1517 affects all users of Piwigo versions prior to 2.7.4 when all filters are activated.
4
What type of vulnerability is CVE-2015-1517?
CVE-2015-1517 is an SQL injection vulnerability that allows execution of arbitrary SQL commands.
5
What parts of Piwigo are impacted by CVE-2015-1517?
CVE-2015-1517 impacts the 'Refresh photo set' action on the batch_manager page within admin.php.