PT-2026-98878 · Piwigo · Piwigo
CVE-2026-42323
·
Published
2026-09-25
·
Updated
2026-09-25
CVSS v3.1
7.2
High
| Vector | AV:N/AC:L/PR:H/UI:N/S:U/C:H/I:H/A:H |
Name of the Vulnerable Software and Affected Versions
Piwigo versions prior to 16.4.0
Description
The application fails to perform numeric validation on dimension width, height, ratio, and filesize values provided via the Batch Manager filter URL in the 'admin/batch manager.php' endpoint. These values are stored in the
bulk manager filter session state and subsequently concatenated into SQL predicates during query construction. An authenticated administrator can exploit this by using crafted filter values to execute time-based or other SQL expressions, which may lead to the disclosure, modification, or disruption of database data.Recommendations
Update to version 16.4.0.
Exploit
Fix
SQL injection
Found an issue in the description? Have something to add? Feel free to write us 👾
Weakness Enumeration
Related Identifiers
Affected Products
Piwigo