Description
Piwigo before 13.6.0 was discovered to contain a SQL injection vulnerability via the order[0][dir] parameter at user_list_backend.php.
Remediation
References
Related Vulnerabilities
Ruby on Rails Improper Input Validation Vulnerability (CVE-2010-3933)
WordPress Plugin Show-Hide/Collapse-Expand Cross-Site Scripting (1.2.5)
Jenkins Insufficient Session Expiration Vulnerability (CVE-2019-1003003)
Roundcube Cross-site Scripting (XSS) Vulnerability (CVE-2015-8864)
WordPress Plugin Smart Slider 2 Multiple Cross-Site Scripting Vulnerabilities (2.3.11)