Description
SQL injection vulnerability found in Piwigo v.13.5.0 and before allows a remote attacker to execute arbitrary code via the filter_user_id parameter to the admin.php?page=history&filter_image_id=&filter_user_id endpoint.
Remediation
References
Related Vulnerabilities
WordPress Plugin ContentStudio Multiple Vulnerabilities (1.2.5)
TCExam Exposure of Sensitive Information to an Unauthorized Actor Vulnerability (CVE-2020-5743)
WordPress Plugin WP Construction Mode Cross-Site Request Forgery (1.91)
WordPress Plugin Rich Table of Contents Cross-Site Scripting (1.3.7)