Software Download Repositoryproduct
http://forge.sigb.net/redmine/projects/pmb/files CVE-2020-37105
HIGH
PMB 5.6 - 'logid' SQL Injection
Record summary
CVE-2020-37105 has a selected CVSS score of 7.1 (high); EIP currently links 1 catalogued exploit.
Description
PMB 5.6 contains a SQL injection vulnerability in the administration download script that allows authenticated attackers to execute arbitrary SQL commands through the 'logid' parameter. Attackers can leverage this vulnerability by sending crafted requests to the /admin/sauvegarde/download.php endpoint with manipulated logid values to interact with the database.
Description source: CVE List
Exploitation context
Available material
- Catalogued exploits
- 1
CISA SSVC decision
ExploitationPoC
AutomatableNo
Technical impactPartial
CISA Coordinator · SSVC 2.0.3 · Evaluated Feb 6, 2026 · Source: CVE List
Affected products and versions
1| Product | Source | Version range | Status |
|---|---|---|---|
| CVE List | 5.6 | affected |
Proofs of concept
1Catalogued exploits
ExploitDBPMB 5.6 - 'logid' SQL InjectionExploitDB exploitby 41-trkNot analyzed1 file
References
5Vendor Homepageproduct
http://www.sigb.net/ nvd.nist.gov
https://nvd.nist.gov/vuln/detail/CVE-2020-37105 ExploitDB-48356exploit
https://www.exploit-db.com/exploits/48356 VulnCheck Advisory: PMB 5.6 - 'logid' SQL InjectionThird-party advisory
https://www.vulncheck.com/advisories/pmb-logid-sql-injection