SQL Injection Vulnerability in Piwigo by Piwigo Team
CVE-2020-19216
8.8HIGH
What is CVE-2020-19216?
A SQL Injection vulnerability exists in the admin/user_perm.php file of Piwigo version 2.9.5. An attacker can exploit this vulnerability via the cat_false parameter in the admin.php?page=group_perm request. This can potentially allow unauthorized access to sensitive database information, posing a significant risk to the integrity and confidentiality of user data.