CVE-2014-125053

MEDIUM

Piwigo-Guest-Book < 1.3.1 - SQL Injection via Navigation Bar start Argument

Title source: llm
STIX 2.1

Description

A vulnerability was found in Piwigo-Guest-Book up to 1.3.0. It has been declared as critical. This vulnerability affects unknown code of the file include/guestbook.inc.php of the component Navigation Bar. The manipulation of the argument start leads to sql injection. Upgrading to version 1.3.1 is able to address this issue. The patch is identified as 0cdd1c388edf15089c3a7541cefe7756e560581d. It is recommended to upgrade the affected component. VDB-217582 is the identifier assigned to this vulnerability.

References (4)

Core 4
Core References
Third Party Advisory, VDB Entry vdb-entry technical-description
https://vuldb.com/?id.217582
Third Party Advisory, VDB Entry signature permissions-required
https://vuldb.com/?ctiid.217582
Release Notes, Third Party Advisory patch
https://github.com/Piwigo/Piwigo-Guest-Book/releases/tag/1.3.1

Scores

CVSS v3 5.5
EPSS 0.0072
EPSS Percentile 50.2%
Attack Vector ADJACENT_NETWORK
CVSS:3.1/AV:A/AC:L/PR:L/UI:N/S:U/C:L/I:L/A:L

Details

CWE
CWE-89
Status published
Products (1)
piwigo/guestbook < 1.3.1
Published Jan 06, 2023
Tracked Since Feb 18, 2026