Software Download Repositoryproduct
http://forge.sigb.net/redmine/projects/pmb/files CVE-2023-53982
CRITICAL
PMB 7.4.6 SQL Injection Vulnerability via Unsanitized Storage Parameter
Record summary
CVE-2023-53982 has a selected CVSS score of 9.3 (critical); EIP currently links 1 catalogued exploit.
Description
PMB 7.4.6 contains a SQL injection vulnerability in the storage parameter of the ajax.php endpoint that allows remote attackers to manipulate database queries. Attackers can exploit the unsanitized 'id' parameter by injecting conditional sleep statements to extract information or perform time-based blind SQL injection attacks.
Description source: CVE List
Exploitation context
Available material
- Catalogued exploits
- 1
CISA SSVC decision
ExploitationPoC
AutomatableYes
Technical impactPartial
CISA Coordinator · SSVC 2.0.3 · Evaluated Dec 23, 2025 · Source: CVE List
Affected products and versions
1| Product | Source | Version range | Status |
|---|---|---|---|
| CVE List | 7.4.6 | affected |
Proofs of concept
1Catalogued exploits
ExploitDBPMB 7.4.6 - SQL InjectionExploitDB exploitby str0xo DZNot analyzed1 file
References
5Vendor Homepageproduct
http://www.sigb.net/ nvd.nist.gov
https://nvd.nist.gov/vuln/detail/CVE-2023-53982 ExploitDB-51197exploit
https://www.exploit-db.com/exploits/51197 VulnCheck Advisory: PMB 7.4.6 SQL Injection Vulnerability via Unsanitized Storage ParameterThird-party advisory
https://www.vulncheck.com/advisories/pmb-sql-injection-vulnerability-via-unsanitized-storage-parameter