Piwigo Improper Neutralization of Special Elements used in an SQL Command (SQL Injection) Vulnerability - CVE-2021-27973 - Vulnerability Database

Piwigo Improper Neutralization of Special Elements used in an SQL Command (SQL Injection) Vulnerability - CVE-2021-27973

High
Reference: CVE-2021-27973
Title: Piwigo Improper Neutralization of Special Elements used in an SQL Command (SQL Injection) Vulnerability
Overview:

SQL injection exists in Piwigo before 11.4.0 via the language parameter to admin.phppagelanguages.