Description
Piwigo before 2.9.3 has SQL injection in admin/tags.php in the administration panel, via the tags array parameter in an admin.php?page=tags request. The attacker must be an administrator.
Remediation
References
Related Vulnerabilities
Oracle JRE CVE-2020-2655 Vulnerability (CVE-2020-2655)
WordPress Plugin Contact Form 7-Clockwork SMS Cross-Site Scripting (2.3.0)
WordPress Plugin FV Flowplayer Video Player Cross-Site Scripting (7.2.0.727)
WordPress 4.3.x Possible SQL Injection Vulnerability (4.3 - 4.3.12)
Moodle Improper Authorization Vulnerability (CVE-2019-14828)