First published: Fri May 06 2022(Updated: )
SQL Injection vulnerability in admin/batch_manager.php in piwigo v2.9.5, via the filter_category parameter to admin.php?page=batch_manager.
Credit: cve@mitre.org
Affected Software | Affected Version | How to fix |
---|---|---|
Piwigo Piwigo | =2.9.5 |
Sign up to SecAlerts for real-time vulnerability data matched to your software, aggregated from hundreds of sources.
The vulnerability ID for this SQL Injection vulnerability is CVE-2020-19217.
The affected software version for this vulnerability is Piwigo v2.9.5.
CVE-2020-19217 has a severity rating of high (8.8).
The CWE category of this vulnerability is CWE-89 (Improper Neutralization of Special Elements used in an SQL Command ('SQL Injection')).
Yes, a fix is available for this vulnerability. Users are advised to upgrade to a patched version of Piwigo.