CVE Watchtower


← Back to CVE List

CVE-2026-49491NVD

Description

Pixa Bank 2.0 contains an SQL injection vulnerability that allows unauthenticated attackers to extract sensitive data by injecting SQL code into the 'rib' parameter. Attackers can send POST requests to the agence-ajax.php endpoint with UNION-based SQL payloads to retrieve user information including names, email addresses, and phone numbers from the database.
Severity Level
HIGH (8.2)
Published Date
01/06/2026
Last Modified
02/06/2026
Exploitation Status
????