CVE-2023-53982

HIGH

PMB 7.4.6 - SQL Injection

Title source: llm

Description

PMB 7.4.6 contains a SQL injection vulnerability in the storage parameter of the ajax.php endpoint that allows remote attackers to manipulate database queries. Attackers can exploit the unsanitized 'id' parameter by injecting conditional sleep statements to extract information or perform time-based blind SQL injection attacks.

Exploits (1)

exploitdb WORKING POC
by str0xo DZ · textwebappsphp
https://www.exploit-db.com/exploits/51197

Scores

CVSS v3 7.5
EPSS 0.0002
EPSS Percentile 6.4%
Attack Vector NETWORK
CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:N/A:N

Details

CWE
CWE-89
Status published
Products (1)
sigb/pmb 7.4.6
Published Dec 23, 2025
Tracked Since Feb 18, 2026