CVE-2017-17822: SQL Injection
Published Dec 21, 2017
·Updated
The List Users API of Piwigo 2.9.2 is vulnerable to SQL Injection via the /admin/userlistbackend.php sSortDir0 parameter. An attacker can exploit this to gain access to the data in a connected MySQL database.
Affected Software
1 affected component
Piwigo piwigo=2.9.2
Event History
Dec 21, 2017
CVE Published
via MITRE·04:00 AM
Data Sourced
via MITRE·04:00 AM
Description
Frequently Asked Questions
1
What is the CVE ID for this vulnerability?
The CVE ID for this vulnerability is CVE-2017-17822.
2
What is the severity of CVE-2017-17822?
The severity of CVE-2017-17822 is medium, with a severity value of 4.9.
3
How does the SQL Injection occur in Piwigo 2.9.2?
The SQL Injection occurs via the /admin/user_list_backend.php sSortDir_0 parameter in Piwigo 2.9.2.
4
What can an attacker do with this vulnerability?
An attacker can gain access to the data in a connected MySQL database.
5
How can I fix the SQL Injection vulnerability in Piwigo 2.9.2?
Update Piwigo to version 2.9.3 or later, which includes a fix for the vulnerability.