module
Piwigo CVE-2023-26876 Gather Credentials via SQL Injection
| Disclosed |
|---|
| Apr 21, 2023 |
Disclosed
Apr 21, 2023
Description
This module allows an authenticated user to retrieve the usernames and encrypted passwords of other users in Piwigo through SQL injection using the (filter_user_id) parameter.
Rapid7 Labs
2026 Global Threat Landscape Report
The predictive window has collapsed. Exploitation follows disclosure in days. See how attackers are accelerating and how to stay ahead.