Showing 1 vulnerability on this page for PMB

Signals CISA KEV Ransomware Nuclei
Redmine vulnerability results
VulnerabilityTitle and contextCVSSEPSSPoCsSignalsSTIX action

PMB 5.6 - 'logid' SQL Injection

PMB 5.6 contains a SQL injection vulnerability in the administration download script that allows authenticated attackers to execute arbitrary SQL commands through the 'logid' parameter. Attackers can leverage this vulnerability by sending crafted requests to the /admin/sauvegarde/download.php endpoint with manipulated logid values to interact with the database.

CWE-89Feb 3, 2026
CVSS7.1v4.0EPSS0.221%PoCs1SignalsNot listed in CISA KEVNo known ransomware useNo Nuclei templatesSTIX