First published: Fri May 06 2022(Updated: )
SQL Injection vulnerability in cat_move.php in piwigo v2.9.5, via the selection parameter to move_categories.
Credit: cve@mitre.org
Affected Software | Affected Version | How to fix |
---|---|---|
Piwigo Piwigo | =2.9.5 |
Sign up to SecAlerts for real-time vulnerability data matched to your software, aggregated from hundreds of sources.
The severity of CVE-2020-19213 is critical.
The SQL Injection vulnerability in cat_move.php affects piwigo v2.9.5 by allowing an attacker to manipulate the selection parameter and perform unauthorized SQL queries.
To fix the SQL Injection vulnerability in cat_move.php, it is recommended to upgrade to a patched version of piwigo that resolves the issue.
No, only version 2.9.5 of piwigo is affected by CVE-2020-19213.
More information about CVE-2020-19213 can be found at the following link: https://github.com/Piwigo/Piwigo/issues/1010