Description
The List Users API of Piwigo 2.9.2 is vulnerable to SQL Injection via the /admin/user_list_backend.php sSortDir_0 parameter. An attacker can exploit this to gain access to the data in a connected MySQL database.
Remediation
References
Related Vulnerabilities
WordPress Plugin Hungred Post Thumbnail 'hpt_file_upload.php' Arbitrary File Upload (2.1.9)
phpMyAdmin Other Vulnerability (CVE-2006-5718)
WordPress Plugin Master Popups Remote Code Execution (1.0.0)
WordPress Plugin WPMovieLibrary Multiple Cross-Site Scripting Vulnerabilities (2.1.4.1)
WordPress Plugin Question Answer Multiple Cross-Site Scripting Vulnerabilities (1.2.30)