Skip to content

Instantly share code, notes, and snippets.

@ZanyMonk
Created November 18, 2025 14:03
Show Gist options
  • Select an option

  • Save ZanyMonk/ed12e265f777152c33aeb806a644850e to your computer and use it in GitHub Desktop.

Select an option

Save ZanyMonk/ed12e265f777152c33aeb806a644850e to your computer and use it in GitHub Desktop.
SIGB PMB 8.0.1.14 - SQLi (CWE-89)
In the "opac_css/ajax_selector.php?completion=bull_num" endpoint, the "id" parameter
can be used to insert an unescaped single quote in the SQL query, allowing to inject
arbitrary SQL via the "datas" parameter.
https://forge.sigb.net/projects/pmb/wiki/Changelog_801#S%C3%A9curit%C3%A9-2
Sign up for free to join this conversation on GitHub. Already have an account? Sign in to comment