VYPR
High severity7.5NVD Advisory· Published Dec 23, 2025· Updated Jun 17, 2026

CVE-2023-53982

CVE-2023-53982

Description

PMB 7.4.6 contains a SQL injection vulnerability in the storage parameter of the ajax.php endpoint that allows remote attackers to manipulate database queries. Attackers can exploit the unsanitized 'id' parameter by injecting conditional sleep statements to extract information or perform time-based blind SQL injection attacks.

AI Insight

LLM-synthesized narrative grounded in this CVE's description and references.

Affected products

3
  • Sigb/Pmb2 versions
    cpe:2.3:a:sigb:pmb:7.4.6:*:*:*:*:*:*:*+ 1 more
    • cpe:2.3:a:sigb:pmb:7.4.6:*:*:*:*:*:*:*
    • (no CPE)range: 7.4.6
  • PMB/PMBllm-fuzzy
    Range: <7.4.6

Patches

Vulnerability mechanics

References

4

News mentions

0

No linked articles in our index yet.