What the vulnerability does
01Description
Improper Neutralization of Special Elements used in an SQL Command ('SQL Injection') vulnerability in Tips and Tricks HQ, Peter Petreski Simple Photo Gallery simple-photo-gallery allows SQL Injection.This issue affects Simple Photo Gallery: from n/a through v1.8.1.
Explanation of Vulnerability in Simple Terms
02Summary
Simple Photo Gallery versions up to 1.8.1 contain a SQL injection vulnerability in database queries. An authenticated administrator can inject malicious SQL code through unfiltered input, allowing them to read, modify, or delete database records. The vulnerability requires high-level admin access and does not affect site availability.
What an attacker can do
03Attacker Capabilities
Read, modify, or delete database records via SQL injection.
Potential impact on your site
04Site Impact
An admin account compromise could expose or corrupt your site's database, including user data and gallery content.
Conditions required to exploit
05Prerequisites
Attacker must have administrator-level access to the site.
Key dates
06Disclosure timeline
November 3, 2023
CVE published
April 28, 2026
Record updated