Piwigo Improper Neutralization of Special Elements used in an SQL Command (SQL Injection) Vulnerability - CVE-2022-26266 - Vulnerability Database

Piwigo Improper Neutralization of Special Elements used in an SQL Command (SQL Injection) Vulnerability - CVE-2022-26266

High
Reference: CVE-2022-26266
Title: Piwigo Improper Neutralization of Special Elements used in an SQL Command (SQL Injection) Vulnerability
Overview:

Piwigo v12.2.0 was discovered to contain a SQL injection vulnerability via pwg.users.php.