Description
Piwigo v11.5 was discovered to contain a SQL injection vulnerability via the parameter pwg_token in /admin/batch_manager_global.php.
Remediation
References
Related Vulnerabilities
Jboss EAP Permissions, Privileges, and Access Controls Vulnerability (CVE-2010-1428)
PHP Uncontrolled Resource Consumption Vulnerability (CVE-2017-11142)
PHP Improper Input Validation Vulnerability (CVE-2016-4537)
TYPO3 CVE-2024-25120 Vulnerability (CVE-2024-25120)
WordPress Plugin Fusion Engage Local File Disclosure (1.0.5)