PT-2025-52840 · Pmb · Pmb

Str0Xo Dz

·

Published

2025-12-23

·

Updated

2025-12-23

·

CVE-2023-53982

CVSS v3.1

7.5

High

VectorAV:N/AC:L/PR:N/UI:N/S:U/C:H/I:N/A:N
Name of the Vulnerable Software and Affected Versions PMB version 7.4.6
Description The software contains a SQL injection issue in the storage parameter of the ''ajax.php'' endpoint. This allows remote attackers to manipulate database queries. The unsanitized id parameter is exploitable by injecting conditional sleep statements to extract information or perform time-based blind SQL injection attacks.
Recommendations Update to a newer version that contains a fix for this vulnerability.

Exploit

Fix

SQL injection

Weakness Enumeration

Related Identifiers

CVE-2023-53982

Affected Products

Pmb