SQL Injection Vulnerability in Pixa Bank 2.0 by Pixa Studio
CVE-2026-49491
Key Information:
- Vendor
Pixastudio
- Status
- Vendor
- CVE Published:
- 1 June 2026
Badges
What is CVE-2026-49491?
Pixa Bank version 2.0 contains a critical SQL injection vulnerability that enables attackers to execute unauthorized SQL code via the 'rib' parameter. By sending specially crafted POST requests to the agence-ajax.php endpoint, invaders can manipulate the database to retrieve sensitive user information, such as names, email addresses, and phone numbers. This exploitation of the SQL injection flaw poses a significant risk to user privacy and confidentiality, making it crucial for organizations using this product to promptly address the vulnerability.
Affected Version(s)
Pixa Bank 2.0
Exploit Proof of Concept (PoC)
PoC code is written by security researchers to demonstrate the vulnerability can be exploited. PoC code is also a key component for weaponization which could lead to ransomware.
References
CVSS V4
Timeline
- ๐ก
Public PoC available
- ๐พ
Exploit known to exist
Vulnerability published
Vulnerability Reserved
