vendor:
PMB Services
by:
Luchador
N/A
CVSS
N/A
Remote SQL Injection
CWE
Product Name: PMB Services
Affected Version From:
Affected Version To: 3.4.2003
Patch Exists: NO
Related CWE:
CPE:
Platforms Tested:
2011
PMB Services <= 3.4.3 Remote SQL Injection
This exploit allows an attacker to execute remote SQL injection in PMB Services version 3.4.3 or below. PMB Services is a free Integrated Library management System. The vulnerability can be exploited by an attacker to gain unauthorized access to the database and potentially retrieve or modify sensitive information.
Mitigation:
The vendor should release a patch to fix the SQL injection vulnerability in PMB Services. In the meantime, users are advised to update to the latest version of the software and implement strict input validation and sanitization to prevent SQL injection attacks.