CVE-2023-53982
HIGHPMB 7.4.6 - SQL Injection via ajax.php Storage Parameter
Title source: llmExploitation Summary
EIP tracks 1 public exploit for CVE-2023-53982. PoCs published by str0xo DZ.
AI-analyzed exploit summary This exploit demonstrates a time-based SQL injection vulnerability in PMB (Integrated Library System) version 7.4.6 and below. The vulnerability is triggered via the 'id' parameter in the 'opac_css/ajax.php' endpoint, allowing an attacker to inject malicious SQL queries.
Description
PMB 7.4.6 contains a SQL injection vulnerability in the storage parameter of the ajax.php endpoint that allows remote attackers to manipulate database queries. Attackers can exploit the unsanitized 'id' parameter by injecting conditional sleep statements to extract information or perform time-based blind SQL injection attacks.
Exploits (1)
This exploit demonstrates a time-based SQL injection vulnerability in PMB (Integrated Library System) version 7.4.6 and below. The vulnerability is triggered via the 'id' parameter in the 'opac_css/ajax.php' endpoint, allowing an attacker to inject malicious SQL queries.
References (4)
Scores
CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:N/A:N