What the vulnerability does
01Description
Improper Neutralization of Special Elements used in an SQL Command ('SQL Injection') vulnerability in Tribulant Slideshow Gallery LITE.This issue affects Slideshow Gallery LITE: from n/a through 1.7.6.
CVSS base score
CVSS vector
CVSS:3.1/AV:N/AC:L/PR:H/UI:N/S:U/C:H/I:H/A:L
What the vulnerability does
Improper Neutralization of Special Elements used in an SQL Command ('SQL Injection') vulnerability in Tribulant Slideshow Gallery LITE.This issue affects Slideshow Gallery LITE: from n/a through 1.7.6.
Explanation of Vulnerability in Simple Terms
Slideshow Gallery LITE versions up to 1.7.6 contain a SQL injection vulnerability in database queries. An authenticated administrator can inject malicious SQL code through unfiltered input, allowing them to read, modify, or delete database records. This vulnerability requires high-level admin access and does not affect site availability.
What an attacker can do
Read, modify, or delete database records via SQL injection.
Potential impact on your site
An admin account compromise could expose or corrupt your site's database, including user data and site configuration.
Conditions required to exploit
Attacker must have administrator-level access to the site.
Key dates
External resources
Related vulnerabilities