First published: Thu Dec 21 2017(Updated: )
The Configuration component of Piwigo 2.9.2 is vulnerable to SQL Injection via the admin/configuration.php order_by array parameter. An attacker can exploit this to gain access to the data in a connected MySQL database.
Credit: cve@mitre.org
Affected Software | Affected Version | How to fix |
---|---|---|
Piwigo Piwigo | =2.9.2 |
Sign up to SecAlerts for real-time vulnerability data matched to your software, aggregated from hundreds of sources.
CVE-2017-17823 is a vulnerability in the Configuration component of Piwigo 2.9.2 that allows SQL Injection via the admin/configuration.php order_by array parameter.
CVE-2017-17823 affects Piwigo version 2.9.2.
CVE-2017-17823 has a severity level of medium with a severity value of 4.9.
An attacker can exploit CVE-2017-17823 to gain access to the data in a connected MySQL database.
To fix CVE-2017-17823, update Piwigo to a version that contains the patch for this vulnerability.