CVE-2017-17824: SQL Injection
The Batch Manager component of Piwigo 2.9.2 is vulnerable to SQL Injection via the admin/batchmanagerunit.php elementids parameter in unit mode. An attacker can exploit this to gain access to the data in a connected MySQL database.
Affected Software
Remediation
Event History
Frequently Asked Questions
What is CVE-2017-17824?
CVE-2017-17824 is a vulnerability in the Batch Manager component of Piwigo 2.9.2 that allows SQL Injection via the admin/batch_manager_unit.php element_ids parameter.
How severe is CVE-2017-17824?
CVE-2017-17824 has a severity rating of 4.9, which is considered medium.
How can an attacker exploit CVE-2017-17824?
An attacker can exploit CVE-2017-17824 by manipulating the element_ids parameter in unit mode of the admin/batch_manager_unit.php file to perform SQL Injection attacks.
What is the affected software version of CVE-2017-17824?
The affected software version of CVE-2017-17824 is Piwigo 2.9.2.
Is there a fix available for CVE-2017-17824?
Yes, a fix for CVE-2017-17824 is available. More information can be found in the provided references.