Description
The List Users API of Piwigo 2.9.2 is vulnerable to SQL Injection via the /admin/user_list_backend.php sSortDir_0 parameter. An attacker can exploit this to gain access to the data in a connected MySQL database.
Remediation
References
Related Vulnerabilities
WordPress Plugin Anthologize Cross-Site Scripting (0.7.7)
WordPress CVE-2016-5836 Vulnerability (CVE-2016-5836)
WordPress Plugin Broken Link Manager SQL Injection (0.6.5)
Moodle Credentials Management Errors Vulnerability (CVE-2014-0008)
WordPress Plugin Fusion:Extension-Menu Multiple Unspecified Vulnerabilities (1.0.2)