Vulnerability Description
SQL injection vulnerability in the administrative backend in Piwigo through 2.9.1 allows remote users to execute arbitrary SQL commands via the cat_false or cat_true parameter in the comments or status page to cat_options.php.
CVSS Score
CRITICAL
Affected Products
| Vendor | Product | Versions |
|---|---|---|
| Piwigo | Piwigo | <= 2.9.1 |
Related Weaknesses (CWE)
References
- http://www.securityfocus.com/bid/99357
- https://github.com/Piwigo/Piwigo/commit/3dd6812412289a199564e63fffd0a9754010b9e0PatchThird Party Advisory
- https://github.com/Piwigo/Piwigo/issues/724ExploitThird Party Advisory
- https://www.exploit-db.com/exploits/43337/
- http://www.securityfocus.com/bid/99357
- https://github.com/Piwigo/Piwigo/commit/3dd6812412289a199564e63fffd0a9754010b9e0PatchThird Party Advisory
- https://github.com/Piwigo/Piwigo/issues/724ExploitThird Party Advisory
- https://www.exploit-db.com/exploits/43337/
FAQ
What is CVE-2017-10682?
CVE-2017-10682 is a vulnerability with a CVSS score of 9.8 (CRITICAL). SQL injection vulnerability in the administrative backend in Piwigo through 2.9.1 allows remote users to execute arbitrary SQL commands via the cat_false or cat_true parameter in the comments or statu...
How severe is CVE-2017-10682?
CVE-2017-10682 has been rated CRITICAL with a CVSS base score of 9.8/10. This is considered a critical vulnerability requiring immediate attention.
Is there a patch for CVE-2017-10682?
Check the references section above for vendor advisories and patch information. Affected products include: Piwigo Piwigo.