CVE-2021-32615: SQL Injection
Published May 13, 2021
·Updated
Piwigo 11.4.0 allows admin/userlistbackend.php order[0][dir] SQL Injection.
Affected Software
1 affected component
Piwigo piwigo=11.4.0
Remediation
Patch Available
Event History
May 13, 2021
CVE Published
via MITRE·10:07 PM
Data Sourced
via MITRE·10:07 PM
Description
Frequently Asked Questions
1
What is CVE-2021-32615?
CVE-2021-32615 is a SQL Injection vulnerability in Piwigo 11.4.0 that allows an attacker to inject malicious SQL queries through the 'order' parameter in the 'admin/user_list_backend.php' script.
2
How severe is CVE-2021-32615?
CVE-2021-32615 has a severity rating of 9.8, which is considered critical.
3
How does CVE-2021-32615 affect Piwigo?
CVE-2021-32615 affects Piwigo version 11.4.0.
4
How can an attacker exploit CVE-2021-32615?
An attacker can exploit CVE-2021-32615 by injecting malicious SQL queries through the 'order' parameter in the 'admin/user_list_backend.php' script.
5
Is there a fix for CVE-2021-32615?
Yes, a fix for CVE-2021-32615 is available in the Piwigo commit 2ce1e5952238eba0fe5c5d6537ebdc76cb970b52.