vendor:
PMB
by:
str0xo DZ (Walid Ben)
7.5
CVSS
HIGH
SQL Injection
89
CWE
Product Name: PMB
Affected Version From: <= 7.4.6
Affected Version To:
Patch Exists: NO
Related CWE:
CPE: a:sigb:pmb:7.4.6
Platforms Tested:
2023
PMB 7.4.6 – SQL Injection
The PMB software version 7.4.6 is vulnerable to SQL Injection. The vulnerability exists in the 'opac_css/ajax.php' URL endpoint. An attacker can exploit this vulnerability by manipulating the 'id' parameter, allowing them to execute arbitrary SQL queries on the database.
Mitigation:
Upgrade to a version higher than 7.4.6 to fix the SQL Injection vulnerability.