9.3
/ 10
CRITICAL
CVSS:4.0/AV:N/AC:L/AT:N/PR:H/UI:N/VC:H/VI:H/VA:N/SC:H/SI:H/SA:H
Description
NextGEN Gallery version prior to 4.2.1 are vulnerable to authenticated SQL injection via the 'orderby' parameter on the REST API endpoints '/imagely/v1/galleries' and '/imagely/v1/albums'.
The root cause is an insufficient sanitization function ('_clean_column()') in the data mapper layer that uses a character blacklist instead of a whitelist approach. This allows an authenticated attacker with the 'NextGEN Gallery overview' capability (assigned to the Administrator role by default) to inject arbitrary SQL into the 'ORDER BY' clause.
The root cause is an insufficient sanitization function ('_clean_column()') in the data mapper layer that uses a character blacklist instead of a whitelist approach. This allows an authenticated attacker with the 'NextGEN Gallery overview' capability (assigned to the Administrator role by default) to inject arbitrary SQL into the 'ORDER BY' clause.
AI Analysis
Authenticated SQL injection vulnerability via the 'orderby' parameter on the REST API endpoints '/imagely/v1/galleries' and '/imagely/v1/albums'
Basic Information
ID
CVE-2026-9059
Source
tenable
Published
May 20, 2026 at 07:41
Modified
May 20, 2026 at 07:59
Affected Product
Vendor
awesomemotive
Product
NextGEN Gallery
Version
prior to 4.2.1
Affected Versions
awesomemotive NextGEN Gallery O
CWE Classification
AI Assessment
AI Score
9.3 / 10
AI Severity
Critical
Vendor
awesomemotive
Product
NextGEN Gallery
Version
prior to 4.2.1