Description
Piwigo before 2.9.3 has SQL injection in admin/tags.php in the administration panel, via the tags array parameter in an admin.php?page=tags request. The attacker must be an administrator.
Remediation
References
Related Vulnerabilities
WordPress Plugin Push Notifications for WordPress (Lite) Cross-Site Request Forgery (6.0)
ReviveAdserver Incorrect Authorization Vulnerability (CVE-2020-8142)
WordPress Plugin Spam Free WordPress Security Bypass (1.9.2)
MySQL CVE-2022-21313 Vulnerability (CVE-2022-21313)
XWiki Insufficiently Protected Credentials Vulnerability (CVE-2022-41933)