Логотип exploitDog
Консоль
Логотип exploitDog

exploitDog

github логотип

GHSA-q8wq-pcxr-7f3j

Опубликовано: 03 фев. 2026
Источник: github
Github: Не прошло ревью
CVSS4: 7.1
CVSS3: 7.1

Описание

PMB 5.6 contains a SQL injection vulnerability in the administration download script that allows authenticated attackers to execute arbitrary SQL commands through the 'logid' parameter. Attackers can leverage this vulnerability by sending crafted requests to the /admin/sauvegarde/download.php endpoint with manipulated logid values to interact with the database.

PMB 5.6 contains a SQL injection vulnerability in the administration download script that allows authenticated attackers to execute arbitrary SQL commands through the 'logid' parameter. Attackers can leverage this vulnerability by sending crafted requests to the /admin/sauvegarde/download.php endpoint with manipulated logid values to interact with the database.

EPSS

Процентиль: 6%
0.00024
Низкий

7.1 High

CVSS4

7.1 High

CVSS3

Дефекты

CWE-89

Связанные уязвимости

CVSS3: 7.1
nvd
4 дня назад

PMB 5.6 contains a SQL injection vulnerability in the administration download script that allows authenticated attackers to execute arbitrary SQL commands through the 'logid' parameter. Attackers can leverage this vulnerability by sending crafted requests to the /admin/sauvegarde/download.php endpoint with manipulated logid values to interact with the database.

EPSS

Процентиль: 6%
0.00024
Низкий

7.1 High

CVSS4

7.1 High

CVSS3

Дефекты

CWE-89