CVE-2014-4649

Piwigo 2.6.x and 2.7.x < 2.7.0beta2 - Authenticated SQL Injection via Photo-Edit Associate Field

Title source: llm
STIX 2.1

Description

SQL injection vulnerability in the photo-edit subsystem in Piwigo 2.6.x and 2.7.x before 2.7.0beta2 allows remote authenticated administrators to execute arbitrary SQL commands via the associate[] field.

References (2)

Core 2
Core References
Various Sources x_refsource_confirm
http://piwigo.org/bugs/view.php?id=3089
Various Sources x_refsource_confirm
http://piwigo.org/bugs/changelog_page.php

Scores

EPSS 0.0101
EPSS Percentile 59.4%

Details

CWE
CWE-89
Status published
Products (5)
piwigo/piwigo 2.6.0
piwigo/piwigo 2.6.1
piwigo/piwigo 2.6.2
piwigo/piwigo 2.6.3
piwigo/piwigo 2.7.0 beta1
Published Jun 28, 2014
Tracked Since Feb 18, 2026