CVE-2019-16119: SQL Injection
Published Sep 8, 2019
·Updated
SQL injection in the photo-gallery (10Web Photo Gallery) plugin before 1.5.35 for WordPress exists via the admin/controllers/Albumsgalleries.php albumid parameter.
Affected Software
1 affected component
10web Photo Gallery Wordpress<1.5.35
Remediation
Event History
Sep 8, 2019
CVE Published
via MITRE·10:48 PM
Data Sourced
via MITRE·10:48 PM
Description
Frequently Asked Questions
1
What is CVE-2019-16119?
CVE-2019-16119 is a SQL injection vulnerability in the photo-gallery (10Web Photo Gallery) plugin before version 1.5.35 for WordPress.
2
How severe is CVE-2019-16119?
CVE-2019-16119 has a severity rating of 9.8 (critical).
3
How does the SQL injection occur in CVE-2019-16119?
SQL injection in CVE-2019-16119 occurs via the admin/controllers/Albumsgalleries.php album_id parameter in the photo-gallery plugin.
4
What software is affected by CVE-2019-16119?
The photo-gallery (10Web Photo Gallery) plugin before version 1.5.35 for WordPress is affected by CVE-2019-16119.
5
How can I fix CVE-2019-16119?
To fix CVE-2019-16119, update the photo-gallery plugin to version 1.5.35 or later.