S4E just found a high-severity finding from top 10 tcp port service scan
PlatformPlansPartners
Resources
ToolsBlogDocs
Sign Up →
high·Product Based Web Vulnerabilities·Updated Jan 3, 2024

CVE-2023-37270 Scanner

CVE-2023-37270 scanner - SQL Injection vulnerability in Piwigo

Est. Time~10 seconds
Scan TypeSingle Scan
Targetsdomain, ipv4, subdomain
CostFree
3.3k
Times Used
continuous scan runs
5.5k
Continuously Checked
assets under CS
0
Vulnerabilities Found
confirmed findings
References
CVECVE-2023-37270
8.8
CVSShigh
Exploitable remotely over the internet · low-privilege account sufficient.

Piwigo is open source photo gallery software. Prior to version 13.8.0, there is a SQL Injection vulnerability in the login of the administrator screen. The SQL statement that acquires the HTTP Header `User-Agent` is vulnerable at the endpoint that records user information when logging in to the administrator screen. It is possible to execute arbitrary SQL statements. Someone who wants to exploit the vulnerability must be log in to the administrator screen, even with low privileges. Any SQL statement can be executed. Doing so may leak information from the database. Version 13.8.0 contains a fix for this issue. As another mitigation, those who want to execute a SQL statement verbatim with user-enterable parameters should be sure to escape the parameter contents appropriately.

Attack Vector
Network
Privileges Req.
Low
User Interaction
None
Affected
Piwigoby Piwigo
< 13.8.0
piwigoby piwigo
AFFECTED< 13.8.0SAFE ✓≥ 13.8.0
Updated Aug 22, 2026View on NVD →
Detail

Piwigo is a popular open-source photo gallery software that allows users to securely store and organize their photos online. It is widely used by individuals, photographers, and businesses alike to keep their photos safe and organized. With its user-friendly interface and intuitive design, Piwigo has become the go-to choice for many who want an easy-to-use yet robust photo gallery software.

CVE-2023-37270 is a SQL Injection vulnerability that was detected in Piwigo prior to version 13.8.0. This vulnerability occurs in the login process for the administrator screen. Essentially, the SQL statement that acquires the HTTP Header 'User-Agent' is vulnerable to exploitation at the endpoint where it records user information during the login process. This provides attackers with an opportunity to execute arbitrary SQL statements.

Exploiting this vulnerability allows attackers to execute any SQL statement, which may leak confidential information from the database. This can lead to a variety of risks, such as data breaches and identity theft. Attackers can steal, modify, or corrupt sensitive information from the affected database, which can have severe consequences for the organization or individual.

If you're concerned about the security of your digital assets, then you'll be pleased to learn that pro features of the s4e.io platform allows you to easily and quickly learn about vulnerabilities in your digital assets. With S4E, you can get instant alerts when vulnerabilities are detected and take proactive steps to secure your digital assets. So, protect your digital assets today and rest easy knowing that you're covered with S4E.

 

REFERENCES

Solution Advice

To protect against this vulnerability, there are a few precautions that can be taken, including:

  • Updating to the latest version of Piwigo.
  • Escaping parameter contents appropriately to prevent SQL injection attacks.
  • Limiting administrator access to only trusted users and checking for unnecessary privilege escalation.
  • Implementing web application firewalls to detect and block attacks before they reach the application.
  • Conducting regular vulnerability assessments and penetration testing to identify any weaknesses in the system.

Get AI-powered remediation steps tailored to your asset.

Try AI Solutions →

Check your infrastructure.
Right now.

11,000+ scanners. Free to start. No credit card required.