SQL Injection Vulnerability in Piwigo 13.6.0 by Piwigo
CVE-2023-33362

9.8CRITICAL

Key Information:

Vendor

Piwigo

Status
Vendor
CVE Published:
23 May 2023

What is CVE-2023-33362?

Piwigo version 13.6.0 suffers from a SQL Injection vulnerability in the 'profile' function. This vulnerability allows attackers to manipulate SQL queries, potentially leading to unauthorized access to the database and sensitive information. It is essential for users of this specific version to apply necessary security updates to mitigate risks associated with exploitation.

References

CVSS V3.1

Score:
9.8
Severity:
CRITICAL
Confidentiality:
High
Integrity:
High
Availability:
High
Attack Vector:
Network
Attack Complexity:
Low
Privileges Required:
None
User Interaction:
None
Scope:
Unchanged

Timeline

  • Vulnerability published

  • Vulnerability Reserved

.