Sploitus

CVE-2023-37270

No indexed exploits for CVE-2023-37270 yet

Piwigo is open source photo gallery software. Prior to version 13.8.0, there is a SQL Injection vulnerability in the login of the administrator screen. The SQL statement that acquires the HTTP Header `User-Agent` is vulnerable at the endpoint that records user information when logging in to the administrator screen. It is possible to execute arbitrary SQL statements. Someone who wants to exploit the vulnerability must be log in to the administrator screen, even with low privileges. Any SQL statement can be executed. Doing so may leak information from the database. Version 13.8.0 contains a fix for this issue. As another mitigation, those who want to execute a SQL statement verbatim with user-enterable parameters should be sure to escape the parameter contents appropriately.

Affected products
Piwigo
Piwigo
< 13.8.0
Fix
Available
CVSS 3.1
8.8 HIGH
EPSS
4.5% (91th percentile)
Weakness
CWE-89
NVD status
Modified
Published
2023-07-07
CVE-2023-37270 at NVD
Authoritative description, scoring and affected products

No indexed exploits for CVE-2023-37270 yet

Our index is partial: it proves presence, never absence

No exploit for CVE-2023-37270 has been indexed yet. Our index is built from live traffic and upstream syncs, so this page can only say what it knows — not that no exploit exists.