CVE-2014-125053
MEDIUMPiwigo-Guest-Book < 1.3.1 - SQL Injection via Navigation Bar start Argument
Title source: llmDescription
A vulnerability was found in Piwigo-Guest-Book up to 1.3.0. It has been declared as critical. This vulnerability affects unknown code of the file include/guestbook.inc.php of the component Navigation Bar. The manipulation of the argument start leads to sql injection. Upgrading to version 1.3.1 is able to address this issue. The patch is identified as 0cdd1c388edf15089c3a7541cefe7756e560581d. It is recommended to upgrade the affected component. VDB-217582 is the identifier assigned to this vulnerability.
References (4)
Core 4
Core References
Third Party Advisory, VDB Entry vdb-entry
technical-description
https://vuldb.com/?id.217582
Third Party Advisory, VDB Entry signature
permissions-required
https://vuldb.com/?ctiid.217582
Patch, Third Party Advisory patch
https://github.com/Piwigo/Piwigo-Guest-Book/commit/0cdd1c388edf15089c3a7541cefe7756e560581d
Release Notes, Third Party Advisory patch
https://github.com/Piwigo/Piwigo-Guest-Book/releases/tag/1.3.1
Scores
CVSS v3
5.5
EPSS
0.0072
EPSS Percentile
50.2%
Attack Vector
ADJACENT_NETWORK
CVSS:3.1/AV:A/AC:L/PR:L/UI:N/S:U/C:L/I:L/A:L
Details
CWE
CWE-89
Status
published
Products (1)
piwigo/guestbook
< 1.3.1
Published
Jan 06, 2023
Tracked Since
Feb 18, 2026