CVE-2017-17823: SQL Injection
Published Dec 21, 2017
·Updated
The Configuration component of Piwigo 2.9.2 is vulnerable to SQL Injection via the admin/configuration.php orderby array parameter. An attacker can exploit this to gain access to the data in a connected MySQL database.
Affected Software
1 affected component
Piwigo piwigo=2.9.2
Event History
Dec 21, 2017
CVE Published
via MITRE·04:00 AM
Data Sourced
via MITRE·04:00 AM
Description
Frequently Asked Questions
1
What is CVE-2017-17823?
CVE-2017-17823 is a vulnerability in the Configuration component of Piwigo 2.9.2 that allows SQL Injection via the admin/configuration.php order_by array parameter.
2
How does CVE-2017-17823 affect Piwigo?
CVE-2017-17823 affects Piwigo version 2.9.2.
3
What is the severity of CVE-2017-17823?
CVE-2017-17823 has a severity level of medium with a severity value of 4.9.
4
How can an attacker exploit CVE-2017-17823?
An attacker can exploit CVE-2017-17823 to gain access to the data in a connected MySQL database.
5
How can I fix CVE-2017-17823?
To fix CVE-2017-17823, update Piwigo to a version that contains the patch for this vulnerability.