2023-05-16 16:11:11 +02:00

28 lines
816 B
JSON

{
"id": "CVE-2023-26876",
"sourceIdentifier": "cve@mitre.org",
"published": "2023-04-21T15:15:07.160",
"lastModified": "2023-04-24T13:02:23.220",
"vulnStatus": "Awaiting Analysis",
"descriptions": [
{
"lang": "en",
"value": "SQL injection vulnerability found in Piwigo v.13.5.0 and before allows a remote attacker to execute arbitrary code via the filter_user_id parameter to the admin.php?page=history&filter_image_id=&filter_user_id endpoint."
}
],
"metrics": {},
"references": [
{
"url": "https://gist.github.com/rodnt/a190d14d1715890d8df19bad58b90693",
"source": "cve@mitre.org"
},
{
"url": "https://piwigo.com",
"source": "cve@mitre.org"
},
{
"url": "https://www.tempest.com.br",
"source": "cve@mitre.org"
}
]
}