CVE-2020-19213: SQL Injection
Published May 6, 2022
·Updated
SQL Injection vulnerability in catmove.php in piwigo v2.9.5, via the selection parameter to movecategories.
Affected Software
1 affected component
Piwigo piwigo=2.9.5
Event History
May 6, 2022
CVE Published
via MITRE·01:55 PM
Data Sourced
via MITRE·01:55 PM
Description
Frequently Asked Questions
1
What is the severity of CVE-2020-19213?
The severity of CVE-2020-19213 is critical.
2
How does SQL Injection vulnerability in cat_move.php affect piwigo v2.9.5?
The SQL Injection vulnerability in cat_move.php affects piwigo v2.9.5 by allowing an attacker to manipulate the selection parameter and perform unauthorized SQL queries.
3
How can I fix the SQL Injection vulnerability in cat_move.php?
To fix the SQL Injection vulnerability in cat_move.php, it is recommended to upgrade to a patched version of piwigo that resolves the issue.
4
Are all versions of piwigo affected by CVE-2020-19213?
No, only version 2.9.5 of piwigo is affected by CVE-2020-19213.
5
Where can I find more information about CVE-2020-19213?
More information about CVE-2020-19213 can be found at the following link: https://github.com/Piwigo/Piwigo/issues/1010