module

Piwigo CVE-2023-26876 Gather Credentials via SQL Injection

Disclosed
Apr 21, 2023
Created
Jul 19, 2023

Description

This module allows an authenticated user to retrieve the usernames and encrypted passwords of other users in Piwigo through SQL injection using the (filter_user_id) parameter.

Authors

rodnt
Rodolfo Tavares
Tempest Security, Henrique Arcoverde

Module Options

To display the available options, load the module within the Metasploit console and run the commands 'show options' or 'show advanced':


msf > use auxiliary/gather/piwigo_cve_2023_26876
msf auxiliary(piwigo_cve_2023_26876) > show actions
...actions...
msf auxiliary(piwigo_cve_2023_26876) > set ACTION < action-name >
msf auxiliary(piwigo_cve_2023_26876) > show options
...show and set options...
msf auxiliary(piwigo_cve_2023_26876) > run

Title
NEW

Explore Exposure Command

Confidently identify and prioritize exposures from endpoint to cloud with full attack surface visibility and threat-aware risk context.