Critical severity9.8NVD Advisory· Published Jun 29, 2017· Updated May 13, 2026
CVE-2017-10682
CVE-2017-10682
Description
SQL injection vulnerability in the administrative backend in Piwigo through 2.9.1 allows remote users to execute arbitrary SQL commands via the cat_false or cat_true parameter in the comments or status page to cat_options.php.
Affected products
1Patches
0No patches discovered yet.
Vulnerability mechanics
AI mechanics synthesis has not run for this CVE yet.
References
4- github.com/Piwigo/Piwigo/commit/3dd6812412289a199564e63fffd0a9754010b9e0nvdPatchThird Party Advisory
- github.com/Piwigo/Piwigo/issues/724nvdExploitThird Party Advisory
- www.securityfocus.com/bid/99357nvd
- www.exploit-db.com/exploits/43337/nvd
News mentions
0No linked articles in our index yet.