CVE-2021-40317: SQL Injection
Published May 26, 2022
·Updated
Piwigo 11.5.0 is affected by a SQL injection vulnerability via admin.php and the id parameter.
Affected Software
1 affected component
Piwigo piwigo=11.5.0
Event History
May 26, 2022
CVE Published
via MITRE·12:04 PM
Data Sourced
via MITRE·12:04 PM
Description
Frequently Asked Questions
1
What is CVE-2021-40317?
CVE-2021-40317 is a SQL injection vulnerability in Piwigo 11.5.0.
2
How does CVE-2021-40317 impact Piwigo?
CVE-2021-40317 allows attackers to perform SQL injection attacks via the admin.php script and the id parameter in Piwigo 11.5.0, potentially compromising the integrity and security of the database.
3
What is the severity of CVE-2021-40317?
CVE-2021-40317 has a severity rating of high (8.8).
4
How can I fix CVE-2021-40317?
To fix CVE-2021-40317, update Piwigo to a version that is not affected by the vulnerability or apply the official patch provided by the Piwigo project.
5
Where can I find more information about CVE-2021-40317?
You can find more information about CVE-2021-40317 on the official Piwigo GitHub repository: https://github.com/Piwigo/Piwigo/issues/1470