Description
The Batch Manager component of Piwigo 2.9.2 is vulnerable to SQL Injection via the admin/batch_manager_unit.php element_ids parameter in unit mode. An attacker can exploit this to gain access to the data in a connected MySQL database.
Remediation
References
Related Vulnerabilities
WordPress Plugin MetaSlider Cross-Site Scripting (2.6.2)
OpenSSL Incomplete Cleanup Vulnerability (CVE-2022-1473)
Joomla Improper Authentication Vulnerability (CVE-2017-16634)
Mailman Improper Control of Generation of Code ('Code Injection') Vulnerability (CVE-2006-4624)
Drupal Incorrect Authorization Vulnerability (CVE-2023-31250)