CVE-2018-6883

Publication date

2018-02-24 16:00:00

Family

mitre

State

PUBLISHED

Description

Piwigo before 2.9.3 has SQL injection in admin/tags.php in the administration panel, via the tags array parameter in an admin.php?page=tags request. The attacker must be an administrator.