First published: Thu May 13 2021(Updated: )
Piwigo 11.4.0 allows admin/user_list_backend.php order[0][dir] SQL Injection.
Credit: cve@mitre.org
Affected Software | Affected Version | How to fix |
---|---|---|
Piwigo Piwigo | =11.4.0 |
Sign up to SecAlerts for real-time vulnerability data matched to your software, aggregated from hundreds of sources.
CVE-2021-32615 is a SQL Injection vulnerability in Piwigo 11.4.0 that allows an attacker to inject malicious SQL queries through the 'order' parameter in the 'admin/user_list_backend.php' script.
CVE-2021-32615 has a severity rating of 9.8, which is considered critical.
CVE-2021-32615 affects Piwigo version 11.4.0.
An attacker can exploit CVE-2021-32615 by injecting malicious SQL queries through the 'order' parameter in the 'admin/user_list_backend.php' script.
Yes, a fix for CVE-2021-32615 is available in the Piwigo commit 2ce1e5952238eba0fe5c5d6537ebdc76cb970b52.