Логотип exploitDog
Консоль
Логотип exploitDog

exploitDog

github логотип

GHSA-2c6v-h7h5-hq25

Опубликовано: 14 янв. 2026
Источник: github
Github: Не прошло ревью
CVSS4: 7.1
CVSS3: 9.8

Описание

VIAVIWEB Wallpaper Admin 1.0 contains an SQL injection vulnerability that allows authenticated attackers to manipulate database queries by injecting SQL code through the img_id parameter. Attackers can send GET requests to edit_gallery_image.php with malicious img_id values to extract database information.

VIAVIWEB Wallpaper Admin 1.0 contains an SQL injection vulnerability that allows authenticated attackers to manipulate database queries by injecting SQL code through the img_id parameter. Attackers can send GET requests to edit_gallery_image.php with malicious img_id values to extract database information.

EPSS

Процентиль: 1%
0.00009
Низкий

7.1 High

CVSS4

9.8 Critical

CVSS3

Дефекты

CWE-89

Связанные уязвимости

CVSS3: 6.5
nvd
25 дней назад

VIAVIWEB Wallpaper Admin 1.0 contains an SQL injection vulnerability that allows authenticated attackers to manipulate database queries by injecting SQL code through the img_id parameter. Attackers can send GET requests to edit_gallery_image.php with malicious img_id values to extract database information.

EPSS

Процентиль: 1%
0.00009
Низкий

7.1 High

CVSS4

9.8 Critical

CVSS3

Дефекты

CWE-89