CVE-2023-27233 | Piwigo 13.5.0 user_list_backend.php order[0][dir] sql injection (ID 1872)
A vulnerability was found in Piwigo 13.5.0. It has been declared as critical. This vulnerability affects unknown code of the file user_list_backend.php. The manipulation of the argument order[0][dir] leads to sql injection.
This vulnerability was named CVE-2023-27233. Access to the local network is required for this attack. There is no exploit available.