CVE-2023-37270 is a high-severity SQL Injection vulnerability (CWE-89) in Piwigo photo gallery software prior to version 13.8.0, specifically within the administrator login's User-Agent handling. An authenticated attacker with low privileges can exploit this to execute arbitrary SQL statements, potentially leading to full compromise of confidentiality, integrity, and availability of the database. While there is no evidence of active exploitation or Metasploit modules, a Nuclei template exists, and the vulnerability has a high EPSS score, indicating a significant threat despite limited community discussion.
| Vendor | Product | Version(s) | CPE |
|---|---|---|---|
< 13.8.0CPE matchmatch criteria | cpe:2.3:a:piwigo:piwigo:*:*:*:*:*:*:*:* |
CVSS version used by this source: 3.1
CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:U/C:H/I:L/A:L
The average CVE in this peer group has 0.0 Twitter, 0.0 Reddit, 0.3 Bluesky, 0.1 Mastodon, and 0.2 GitHub mentions.
No media coverage found for this CVE.
The average CVE in this peer group has 0.1 InfoSec Media, 0.0 Vendor Blog, and 0.0 Security Researcher mentions.