PMB 7.4.6 contains a SQL injection vulnerability in the storage parameter of the ajax.php endpoint that allows remote attackers to manipulate database queries. Attackers can exploit the unsanitized 'id' parameter by injecting conditional sleep statements to extract information or perform time-based blind SQL injection attacks.
History

Tue, 23 Dec 2025 19:45:00 +0000

Type Values Removed Values Added
Description PMB 7.4.6 contains a SQL injection vulnerability in the storage parameter of the ajax.php endpoint that allows remote attackers to manipulate database queries. Attackers can exploit the unsanitized 'id' parameter by injecting conditional sleep statements to extract information or perform time-based blind SQL injection attacks.
Title PMB 7.4.6 SQL Injection Vulnerability via Unsanitized Storage Parameter
Weaknesses CWE-89
References
Metrics cvssV3_1

{'score': 8.2, 'vector': 'CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:L/A:N'}

cvssV4_0

{'score': 9.3, 'vector': 'CVSS:4.0/AV:N/AC:L/AT:N/PR:N/UI:N/VC:H/VI:H/VA:L/SC:N/SI:N/SA:N'}


cve-icon MITRE

Status: PUBLISHED

Assigner: VulnCheck

Published:

Updated: 2025-12-23T21:39:54.214Z

Reserved: 2025-12-20T16:31:20.900Z

Link: CVE-2023-53982

cve-icon Vulnrichment

No data.

cve-icon NVD

Status : Received

Published: 2025-12-23T20:15:46.073

Modified: 2025-12-23T20:15:46.073

Link: CVE-2023-53982

cve-icon Redhat

No data.

cve-icon OpenCVE Enrichment

No data.