PT-2026-44217 · 10Web+1 · Photo Gallery By 10Web – Mobile-Friendly Image Gallery+1
CVSS v3.1
6.5
Medium
| Vector | AV:N/AC:L/PR:L/UI:N/S:U/C:H/I:N/A:N |
Name of the Vulnerable Software and Affected Versions
The Photo Gallery by 10Web – Mobile-Friendly Image Gallery versions prior to 1.8.41
Description
An issue exists due to insufficient escaping of user-supplied parameters and lack of preparation in SQL queries. Authenticated attackers with contributor-level access or higher can perform a time-based blind SQL Injection—a technique used to extract information from a database by observing the time it takes for the server to respond to specific queries. This is achieved by embedding a malicious shortcode in a post or draft, which executes the injected SQL when the shortcode is rendered via the
order by parameter.Recommendations
Update the plugin to a version later than 1.8.40.
Avoid using the
order by parameter in shortcodes until the update is applied.Fix
SQL injection
Found an issue in the description? Have something to add? Feel free to write us 👾
Weakness Enumeration
Related Identifiers
Affected Products
Photo Gallery By 10Web – Mobile-Friendly Image Gallery
Photo Gallery