Lucene search

K
prionPRIOn knowledge basePRION:CVE-2023-26876
HistoryApr 21, 2023 - 3:15 p.m.

Sql injection

2023-04-2115:15:00
PRIOn knowledge base
www.prio-n.com
7
sql injection
piwigo
remote attacker
arbitrary code
filter_user_id parameter
admin.php endpoint
nvd

9 High

AI Score

Confidence

High

0.022 Low

EPSS

Percentile

89.5%

SQL injection vulnerability found in Piwigo v.13.5.0 and before allows a remote attacker to execute arbitrary code via the filter_user_id parameter to the admin.php?page=history&filter_image_id=&filter_user_id endpoint.

CPENameOperatorVersion
piwigole13.5.0

9 High

AI Score

Confidence

High

0.022 Low

EPSS

Percentile

89.5%