Description
SQL injection vulnerability found in Piwigo v.13.5.0 and before allows a remote attacker to execute arbitrary code via the filter_user_id parameter to the admin.php?page=history&filter_image_id=&filter_user_id endpoint.
Remediation
References
Related Vulnerabilities
Coppermine Exposure of Sensitive Information to an Unauthorized Actor Vulnerability (CVE-2015-3923)
WordPress 4.2.x Multiple Vulnerabilities (4.2 - 4.2.19)
MODX Unrestricted Upload of File with Dangerous Type Vulnerability (CVE-2022-26149)
WordPress Plugin My Page Order Cross-Site Scripting (4.3)
MediaWiki Improper Input Validation Vulnerability (CVE-2013-1816)