First published: Fri May 06 2022(Updated: )
SQL Injection vulnerability in admin/group_list.php in piwigo v2.9.5, via the group parameter to delete.
Credit: cve@mitre.org
Affected Software | Affected Version | How to fix |
---|---|---|
Piwigo Piwigo | =2.9.5 |
Sign up to SecAlerts for real-time vulnerability data matched to your software, aggregated from hundreds of sources.
CVE-2020-19212 is a SQL Injection vulnerability in admin/group_list.php in piwigo v2.9.5.
CVE-2020-19212 allows an attacker to perform SQL Injection by exploiting the 'group' parameter in admin/group_list.php in Piwigo v2.9.5.
The severity of CVE-2020-19212 is medium with a CVSS score of 4.9.
To fix CVE-2020-19212, upgrade to a version of Piwigo that is not affected by this vulnerability.
More information about CVE-2020-19212 can be found at the following link: <a href='https://github.com/Piwigo/Piwigo/issues/1009'>https://github.com/Piwigo/Piwigo/issues/1009</a>