PT-2025-48069 · Sigb Pmb · Sigb Pmb

CVE-2025-61167

·

Publicado

2025-11-25

·

Atualizado

2025-12-01

CVSS v3.1

6.5

Média

VetorAV:N/AC:L/PR:N/UI:N/S:U/C:L/I:L/A:N
Name of the Vulnerable Software and Affected Versions SIGB PMB version 8.0.1.14
Description The software contains multiple SQL injection flaws in the /opac css/ajax selector.php component. These flaws are triggered through the id and datas parameters. The component is susceptible to manipulation via crafted input to these parameters, potentially allowing unauthorized database access or modification.
Recommendations Apply updates to address the identified SQL injection flaws in the /opac css/ajax selector.php component. As a temporary workaround, restrict access to the id and datas parameters in the /opac css/ajax selector.php component.

Correção

SQL injection

Encontrou algum problema na descrição? Tem algo a acrescentar? Fique à vontade para nos escrever 👾

Enumeração de Fraquezas

Identificadores relacionados

CVE-2025-61167

Produtos afetados

Sigb Pmb