CVE-2023-26876: SQL Injection
SQL injection vulnerability found in Piwigo v.13.5.0 and before allows a remote attacker to execute arbitrary code via the filteruserid parameter to the admin.php?page=history&filterimageid=&filteruserid endpoint.
Affected Software
Event History
Frequently Asked Questions
What is CVE-2023-26876?
CVE-2023-26876 is a SQL injection vulnerability found in Piwigo v.13.5.0 and before.
How does CVE-2023-26876 impact Piwigo?
CVE-2023-26876 allows a remote attacker to execute arbitrary code in Piwigo via the filter_user_id parameter.
What is the severity of CVE-2023-26876?
CVE-2023-26876 has a severity rating of 8.8 (high).
How can I fix CVE-2023-26876 in Piwigo?
To fix CVE-2023-26876 in Piwigo, make sure to update to a version higher than 13.5.0.
Where can I find more information about CVE-2023-26876?
You can find more information about CVE-2023-26876 in the following references: [1](http://packetstormsecurity.com/files/172059/Piwigo-13.5.0-SQL-Injection.html), [2](http://seclists.org/fulldisclosure/2023/Apr/13), [3](https://gist.github.com/rodnt/a190d14d1715890d8df19bad58b90693).