Description
SQL injection exists in Piwigo before 11.4.0 via the language parameter to admin.php?page=languages.
Remediation
References
Related Vulnerabilities
WordPress Plugin Clockwork SMS Notfications Cross-Site Scripting (2.0.3)
WordPress Plugin BuddyPress Multiple SQL Injection Vulnerabilities (1.7.1)
WebLogic Deserialization of Untrusted Data Vulnerability (CVE-2018-2628)
WordPress Plugin WP Easy Slideshow Multiple Cross-Site Request Forgery Vulnerabilities (1.0.3)