Description
The List Users API of Piwigo 2.9.2 is vulnerable to SQL Injection via the /admin/user_list_backend.php sSortDir_0 parameter. An attacker can exploit this to gain access to the data in a connected MySQL database.
Remediation
References
Related Vulnerabilities
Java Unspesificed Vulnerability (CVE-2018-3169)
WordPress Plugin Yoast SEO SQL Injection (1.7.3.3)
WordPress Plugin Affiliates Manager Unspecified Vulnerability (2.7.7)
Drupal Core 9.0.x Cross-Site Request Forgery (9.0.0 - 9.0.14)
WordPress Plugin InstaWP Connect-1-click WP Staging & Migration Security Bypass (0.1.0.44)