CVE-2020-19217: SQL Injection
Published May 6, 2022
·Updated
SQL Injection vulnerability in admin/batchmanager.php in piwigo v2.9.5, via the filtercategory parameter to admin.php?page=batchmanager.
Affected Software
1 affected component
Piwigo piwigo=2.9.5
Event History
May 6, 2022
CVE Published
via MITRE·01:55 PM
Data Sourced
via MITRE·01:55 PM
Description
Frequently Asked Questions
1
What is the vulnerability ID for this SQL Injection vulnerability?
The vulnerability ID for this SQL Injection vulnerability is CVE-2020-19217.
2
What is the affected software version for this vulnerability?
The affected software version for this vulnerability is Piwigo v2.9.5.
3
What is the severity rating of CVE-2020-19217?
CVE-2020-19217 has a severity rating of high (8.8).
4
What is the CWE category of this vulnerability?
The CWE category of this vulnerability is CWE-89 (Improper Neutralization of Special Elements used in an SQL Command ('SQL Injection')).
5
Is there a fix available for this vulnerability?
Yes, a fix is available for this vulnerability. Users are advised to upgrade to a patched version of Piwigo.