CVE-2023-53982

PMB 7.4.6 contains a SQL injection vulnerability in the storage parameter of the ajax.php endpoint that allows remote attackers to manipulate database queries. Attackers can exploit the unsanitized 'id' parameter by injecting conditional sleep statements to extract information or perform time-based blind SQL injection attacks.
Configurations

Configuration 1 (hide)

cpe:2.3:a:sigb:pmb:7.4.6:*:*:*:*:*:*:*

History

16 Jan 2026, 19:16

Type Values Removed Values Added
CVSS v2 : unknown
v3 : 8.2
v2 : unknown
v3 : 7.5

14 Jan 2026, 20:03

Type Values Removed Values Added
CPE cpe:2.3:a:sigb:pmb:7.4.6:*:*:*:*:*:*:*
References () http://forge.sigb.net/redmine/projects/pmb/files - () http://forge.sigb.net/redmine/projects/pmb/files - Product
References () http://www.sigb.net - () http://www.sigb.net - Product
References () https://www.exploit-db.com/exploits/51197 - () https://www.exploit-db.com/exploits/51197 - Exploit, Third Party Advisory
References () https://www.vulncheck.com/advisories/pmb-sql-injection-vulnerability-via-unsanitized-storage-parameter - () https://www.vulncheck.com/advisories/pmb-sql-injection-vulnerability-via-unsanitized-storage-parameter - Third Party Advisory
First Time Sigb
Sigb pmb

23 Dec 2025, 20:15

Type Values Removed Values Added
New CVE

Information

Published : 2025-12-23 20:15

Updated : 2026-01-16 19:16


NVD link : CVE-2023-53982

Mitre link : CVE-2023-53982

CVE.ORG link : CVE-2023-53982


JSON object : View

Products Affected

sigb

  • pmb
CWE
CWE-89

Improper Neutralization of Special Elements used in an SQL Command ('SQL Injection')