CVE-2022-1281: Photo Gallery < 1.6.3 - Unauthenticated SQL Injection
Published May 2, 2022
·Updated
The Photo Gallery WordPress plugin through 1.6.3 does not properly escape the $POST['filtertag'] parameter, which is appended to an SQL query, making SQL Injection attacks possible.
Affected Software
1 affected component
10web Photo Gallery Wordpress<=1.6.3
Remediation
Event History
May 2, 2022
CVE Published
via MITRE·04:05 PM
Data Sourced
via MITRE·04:05 PM
DescriptionWeakness
Frequently Asked Questions
1
What is the vulnerability ID for this vulnerability?
The vulnerability ID for this vulnerability is CVE-2022-1281.
2
What is the severity of CVE-2022-1281?
The severity of CVE-2022-1281 is critical with a severity value of 9.8.
3
What is the affected software for CVE-2022-1281?
The affected software for CVE-2022-1281 is the Photo Gallery WordPress plugin version up to and including 1.6.3.
4
What is the CWE category for CVE-2022-1281?
The CWE category for CVE-2022-1281 is CWE-89 (SQL Injection).
5
How can I fix CVE-2022-1281?
To fix CVE-2022-1281, update the Photo Gallery WordPress plugin to version 1.6.4 or higher.