“User-Agent”中的 Piwigo SQL 注入漏洞 (CVE-2023-37270)

admin 2023-11-29 22:48:47 Ali_nvd 来源:ZONE.CI 全球网 0 阅读模式
“User-Agent”中的 Piwigo SQL 注入漏洞 (CVE-2023-37270)

CVE编号

CVE-2023-37270

利用情况

暂无

补丁情况

N/A

披露时间

2023-07-08
漏洞描述
Piwigo is open source photo gallery software. Prior to version 13.8.0, there is a SQL Injection vulnerability in the login of the administrator screen. The SQL statement that acquires the HTTP Header `User-Agent` is vulnerable at the endpoint that records user information when logging in to the administrator screen. It is possible to execute arbitrary SQL statements. Someone who wants to exploit the vulnerability must be log in to the administrator screen, even with low privileges. Any SQL statement can be executed. Doing so may leak information from the database. Version 13.8.0 contains a fix for this issue. As another mitigation, those who want to execute a SQL statement verbatim with user-enterable parameters should be sure to escape the parameter contents appropriately.
解决建议
建议您更新当前系统或软件至最新版,完成漏洞的修复。
参考链接
https://github.com/Piwigo/Piwigo/blob/c01ec38bc43f09424a8d404719c35f963d63cf0...
https://github.com/Piwigo/Piwigo/blob/c01ec38bc43f09424a8d404719c35f963d63cf0...
https://github.com/Piwigo/Piwigo/commit/978425527d6c113887f845d75cf982bbb62d761a
https://github.com/Piwigo/Piwigo/security/advisories/GHSA-934w-qj9p-3qcx
https://piwigo.org/release-13.8.0
受影响软件情况
# 类型 厂商 产品 版本 影响面
1
运行在以下环境
应用 piwigo piwigo * Up to (excluding) 13.8.0
CVSS3评分 8.8
  • 攻击路径 网络
  • 攻击复杂度 低
  • 权限要求 低
  • 影响范围 未更改
  • 用户交互 无
  • 可用性 高
  • 保密性 高
  • 完整性 高
CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H
CWE-ID 漏洞类型
CWE-89 SQL命令中使用的特殊元素转义处理不恰当(SQL注入)
- avd.aliyun.com
weinxin
版权声明
本站原创文章转载请注明文章出处及链接,谢谢合作!
N/A Ali_nvd

N/A

N/ACVE编号 CVE-2024-9120利用情况 暂无补丁情况 N/A披露时间 2024-09-23漏洞描述Use after free in Dawn
评论:0   参与:  0