CVE-2023-53982

PMB 7.4.6 contains a SQL injection vulnerability in the storage parameter of the ajax.php endpoint that allows remote attackers to manipulate database queries. Attackers can exploit the unsanitized 'id' parameter by injecting conditional sleep statements to extract information or perform time-based blind SQL injection attacks.
Configurations

Configuration 1 (hide)

cpe:2.3:a:sigb:pmb:7.4.6:*:*:*:*:*:*:*

History

No history.

Information

Published : 2025-12-23 20:15

Updated : 2026-01-16 19:16


NVD link : CVE-2023-53982

Mitre link : CVE-2023-53982

CVE.ORG link : CVE-2023-53982


JSON object : View

Products Affected

sigb

  • pmb
CWE
CWE-89

Improper Neutralization of Special Elements used in an SQL Command ('SQL Injection')