CVE-2026-49491

Pixa Bank 2.0 contains an SQL injection vulnerability that allows unauthenticated attackers to extract sensitive data by injecting SQL code into the 'rib' parameter. Attackers can send POST requests to the agence-ajax.php endpoint with UNION-based SQL payloads to retrieve user information including names, email addresses, and phone numbers from the database.
Configurations

No configuration.

History

22 Jul 2026, 17:10

Type Values Removed Values Added
Summary
  • (es) Pixa Bank 2.0 contiene una vulnerabilidad de inyección SQL que permite a atacantes no autenticados extraer datos sensibles inyectando código SQL en el parámetro 'rib'. Los atacantes pueden enviar solicitudes POST al endpoint agence-ajax.php con payloads SQL basados en UNION para recuperar información de usuario incluyendo nombres, direcciones de correo electrónico y números de teléfono de la base de datos.

01 Jun 2026, 22:16

Type Values Removed Values Added
New CVE

Information

Published : 2026-06-01 22:16

Updated : 2026-07-22 18:10


NVD link : CVE-2026-49491

Mitre link : CVE-2026-49491

CVE.ORG link : CVE-2026-49491


JSON object : View

Products Affected

No product.

CWE
CWE-89

Improper Neutralization of Special Elements used in an SQL Command ('SQL Injection')