First published: Fri Apr 02 2021(Updated: )
SQL injection exists in Piwigo before 11.4.0 via the language parameter to admin.php?page=languages.
Credit: cve@mitre.org
Affected Software | Affected Version | How to fix |
---|---|---|
Piwigo Piwigo | <11.4.0 |
Sign up to SecAlerts for real-time vulnerability data matched to your software, aggregated from hundreds of sources.
CVE-2021-27973 is a SQL injection vulnerability in Piwigo before version 11.4.0.
CVE-2021-27973 occurs via the language parameter to the admin.php?page=languages endpoint in Piwigo.
The severity of CVE-2021-27973 is high, with a CVSS score of 7.2.
To fix CVE-2021-27973, upgrade Piwigo to version 11.4.0 or later.
You can find more information about CVE-2021-27973 at the following references: [Packet Storm Security](http://packetstormsecurity.com/files/162404/Piwigo-11.3.0-SQL-Injection.html) and [GitHub Piwigo](https://github.com/Piwigo/Piwigo/issues/1352).