Vulnerability Description
PMB 7.4.6 contains a SQL injection vulnerability in the storage parameter of the ajax.php endpoint that allows remote attackers to manipulate database queries. Attackers can exploit the unsanitized 'id' parameter by injecting conditional sleep statements to extract information or perform time-based blind SQL injection attacks.
CVSS Score
HIGH
Affected Products
| Vendor | Product | Versions |
|---|---|---|
| Sigb | Pmb | 7.4.6 |
Related Weaknesses (CWE)
References
- http://forge.sigb.net/redmine/projects/pmb/filesProduct
- http://www.sigb.netProduct
- https://www.exploit-db.com/exploits/51197ExploitThird Party Advisory
- https://www.vulncheck.com/advisories/pmb-sql-injection-vulnerability-via-unsanitThird Party Advisory
FAQ
What is CVE-2023-53982?
CVE-2023-53982 is a vulnerability with a CVSS score of 7.5 (HIGH). PMB 7.4.6 contains a SQL injection vulnerability in the storage parameter of the ajax.php endpoint that allows remote attackers to manipulate database queries. Attackers can exploit the unsanitized 'i...
How severe is CVE-2023-53982?
CVE-2023-53982 has been rated HIGH with a CVSS base score of 7.5/10. Review the CVSS metrics above for detailed severity breakdown.
Is there a patch for CVE-2023-53982?
Check the references section above for vendor advisories and patch information. Affected products include: Sigb Pmb.