Unrated severityNVD Advisory· Published Jun 18, 2026
SQL Injection in LMS
CVE-2026-40455
Description
An SQL Injection vulnerability exists in LMS (LAN Management System) before commit 4cb30a7 within the "tarifflist.php" module due to insufficient sanitization of the POST "tg[]" parameter. The application directly concatenates user-supplied array values into an SQL query using "implode()", allowing authenticated attackers to perform Error-Based SQL injection and extract sensitive database information.
AI Insight
LLM-synthesized narrative grounded in this CVE's description and references.
Affected products
1- Range: <=4cb30a7
Patches
Vulnerability mechanics
References
3- github.com/chilek/lms/commit/4cb30a70e7e3d8a0ea53afa2dbef19d5243d449bmitrepatch
- cert.pl/posts/2026/06/CVE-2026-40455mitrethird-party-advisory
- lms.org.plmitreproduct
News mentions
0No linked articles in our index yet.