Description
The List Users API of Piwigo 2.9.2 is vulnerable to SQL Injection via the /admin/user_list_backend.php sSortDir_0 parameter. An attacker can exploit this to gain access to the data in a connected MySQL database.
Remediation
References
Related Vulnerabilities
Oracle JRE CVE-2020-2754 Vulnerability (CVE-2020-2754)
WordPress Plugin Sports Rankings and Lists Cross-Site Scripting (3.5)
WordPress Plugin Import any XML or CSV File to WordPress Arbitrary File Upload (3.6.7)
WordPress Plugin Two Factor Authentication Cross-Site Request Forgery (1.3.12)
WordPress Plugin Facebook Page Photo Gallery Cross-Site Scripting (2.0.9)