Description SQL Injection vulnerability in admin/group_list.php in piwigo v2.9.5, via the group parameter to delete. Remediation References CVE-2020-19212 Related Vulnerabilities Django Exposure of Sensitive Information to an Unauthorized Actor Vulnerability (CVE-2016-2513) MySQL CVE-2023-22007 Vulnerability (CVE-2023-22007) MySQL CVE-2019-2482 Vulnerability (CVE-2019-2482) MODX Improper Limitation of a Pathname to a Restricted Directory ('Path Traversal') Vulnerability (CVE-2016-10039) WordPress Plugin Top 10-Popular posts for WordPress Cross-Site Request Forgery (1.9.2) Severity Medium Classification CVE-2020-19212 CWE-138 CVSS:3.1/AV:N/AC:L/PR:H/UI:N/S:U/C:H/I:N/A:N CVSS:4.0/AV:N/AC:L/AT:N/PR:H/UI:N/VC:H/VI:N/VA:N/SC:N/SI:N/SA:N Tags Missing Update Known Vulnerabilities