A SQL Injection vulnerability in /admin/convert/export.class.php in PMB 7.4.7 and earlier versions allows remote unauthenticated attackers to execute arbitrary SQL commands via the query parameter in get_next_notice function.
Metrics
Affected Vendors & Products
References
History
Tue, 25 Mar 2025 17:15:00 +0000
Type | Values Removed | Values Added |
---|---|---|
First Time appeared |
Sigb
Sigb pmb |
|
CPEs | cpe:2.3:a:sigb:pmb:*:*:*:*:*:*:*:* | |
Vendors & Products |
Sigb
Sigb pmb |
Tue, 27 Aug 2024 20:00:00 +0000
Type | Values Removed | Values Added |
---|---|---|
Weaknesses | CWE-89 | |
Metrics |
cvssV3_1
|

Status: PUBLISHED
Assigner: mitre
Published:
Updated: 2024-08-27T18:47:25.178Z
Reserved: 2023-12-26T00:00:00
Link: CVE-2023-51828

Updated: 2024-08-02T22:48:11.334Z

Status : Analyzed
Published: 2024-02-21T22:15:48.960
Modified: 2025-03-25T16:53:02.680
Link: CVE-2023-51828

No data.