CVE-2023-53982
HIGHPMB 7.4.6 - SQL Injection
Title source: llmDescription
PMB 7.4.6 contains a SQL injection vulnerability in the storage parameter of the ajax.php endpoint that allows remote attackers to manipulate database queries. Attackers can exploit the unsanitized 'id' parameter by injecting conditional sleep statements to extract information or perform time-based blind SQL injection attacks.
Exploits (1)
References (4)
Scores
CVSS v3
7.5
EPSS
0.0002
EPSS Percentile
6.4%
Attack Vector
NETWORK
CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:N/A:N
Details
CWE
CWE-89
Status
published
Products (1)
sigb/pmb
7.4.6
Published
Dec 23, 2025
Tracked Since
Feb 18, 2026