SQL Injection Vulnerability in PMB 5.6 Administration Download Script
CVE-2020-37105
Key Information:
Badges
What is CVE-2020-37105?
PMB 5.6 is affected by a SQL injection vulnerability located in the administration download script. An attacker with valid credentials can exploit this vulnerability by altering the 'logid' parameter, sending specially crafted requests to the /admin/sauvegarde/download.php endpoint. This allows unauthorized database interactions, potentially leading to data leakage or manipulation. It's crucial for administrators using PMB 5.6 to be aware of this vulnerability and apply necessary security practices.
Affected Version(s)
PMB 5.6
Exploit Proof of Concept (PoC)
PoC code is written by security researchers to demonstrate the vulnerability can be exploited. PoC code is also a key component for weaponization which could lead to ransomware.
References
CVSS V4
Timeline
- ๐ก
Public PoC available
- ๐พ
Exploit known to exist
Vulnerability published
Vulnerability Reserved
