CVE-2026-49491

Pixa Bank 2.0 contains an SQL injection vulnerability that allows unauthenticated attackers to extract sensitive data by injecting SQL code into the 'rib' parameter. Attackers can send POST requests to the agence-ajax.php endpoint with UNION-based SQL payloads to retrieve user information including names, email addresses, and phone numbers from the database.
Configurations

No configuration.

History

01 Jun 2026, 22:16

Type Values Removed Values Added
New CVE

Information

Published : 2026-06-01 22:16

Updated : 2026-06-02 14:43


NVD link : CVE-2026-49491

Mitre link : CVE-2026-49491

CVE.ORG link : CVE-2026-49491


JSON object : View

Products Affected

No product.

CWE
CWE-89

Improper Neutralization of Special Elements used in an SQL Command ('SQL Injection')