Piwigo CVE-2023-26876 Gather Credentials via SQL Injection
Title source: metasploitExploitation Summary
EIP tracks 2 public exploits for CVE-2023-26876.
PoCs published by incogbyte, rodnt, Rodolfo Tavares, Tempest Security, Henrique Arcoverde, including Metasploit module auxiliary/gather/piwigo_cve_2023_26876.
AI-analyzed exploit summary The repository contains functional exploit code for CVE-2023-26876, which targets Piwigo via SQL injection. The exploit is written in Ruby and appears to be a Metasploit module designed to gather credentials.
Description
SQL injection vulnerability found in Piwigo v.13.5.0 and before allows a remote attacker to execute arbitrary code via the filter_user_id parameter to the admin.php?page=history&filter_image_id=&filter_user_id endpoint.
Exploits (2)
The repository contains functional exploit code for CVE-2023-26876, which targets Piwigo via SQL injection. The exploit is written in Ruby and appears to be a Metasploit module designed to gather credentials.
This Metasploit module exploits an authenticated SQL injection vulnerability in Piwigo via the `filter_user_id` parameter to dump usernames and password hashes from the database.
References (5)
Scores
CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H