PMB 5.6 - 'logid' SQL Injection
Vulnerability Description
PMB 5.6 contains a SQL injection vulnerability in the administration download script that allows authenticated attackers to execute arbitrary SQL commands through the 'logid' parameter. Attackers can leverage this vulnerability by sending crafted requests to the /admin/sauvegarde/download.php endpoint with manipulated logid values to interact with the database.
Impact Analysis
Refer to official advisory for detailed impact metrics.
Remediation
Ensure systems are updated to the latest vendor-supplied patch levels.
Am I Vulnerable?
Launch our assessment wizard to check if your infrastructure is exposed to • CVE-2020-37105
Credits & Attribution
The following person or organization is credited with identifying this vulnerability, as recorded in the NVD database:
- 41-trk (Tarik Bakir)
References
More from redmine
View All →Affected Vendor
redmine
View all reports →