Description

Multiple vulnerabilities exist in Maian Gallery, including SQL injection and cross-site scripting. Input parameters are not properly validated for database operations or HTML rendering.

Impact

SQL injection enables extraction of database contents. XSS allows session hijacking and potential compromise of administrator accounts.

Solution

Upgrade to the latest version of Maian Gallery.

References