Piwigo Improper Neutralization of Special Elements used in an SQL Command (SQL Injection) Vulnerability - CVE-2021-40313 - Vulnerability Database
Piwigo Improper Neutralization of Special Elements used in an SQL Command (SQL Injection) Vulnerability - CVE-2021-40313
High
Reference:
CVE-2021-40313
Title:
Piwigo Improper Neutralization of Special Elements used in an SQL Command (SQL Injection) Vulnerability
Overview:
Piwigo v11.5 was discovered to contain a SQL injection vulnerability via the parameter pwg_token in /admin/batch_manager_global.php.