CRITICAL🇵🇱 Wersja polska

CVE-2026-25238

CVSS 9.2v4.0pub. 2026-02-03upd. 2026-02-05

PEAR is a framework and distribution system for reusable PHP components. Prior to version 1.33.0, a SQL injection vulnerability in bug subscription deletion may allow attackers to inject SQL via a crafted email value. This issue has been patched in version 1.33.0.

🤖 AI Analysis
How it works

The vulnerability results from the lack of proper validation and parameterization of user input passed in the email address field during the bug subscription deletion operation. An attacker can provide a crafted email value containing malicious SQL code fragments, which will be directly included in the executed database query. This technique allows manipulation of the logic of SQL queries executed by the application.

Impact

Successful exploitation of this vulnerability may allow an attacker to perform unauthorized read, modification, or deletion of data stored in the PEAR Pearweb application database. Depending on the database configuration, it is also possible to escalate the attack to further infrastructure layers.

Mitigation & patch

PEAR Pearweb should be updated to version 1.33.0 or later, in which the vulnerability has been patched. Detailed information is available in the vendor's references at: https://github.com/pear/pearweb/security/advisories/GHSA-cv3c-27h5-7gmv

Who is affected

PEAR Pearweb versions prior to 1.33.0

Analysis generated by Claude AI (Anthropic) based on NVD data. Always verify with vendor.
CVSS Vector
CVSS:4.0/AV:N/AC:L/AT:P/PR:N/UI:N/VC:H/VI:H/VA:H/SC:N/SI:N/SA:N/E:X/CR:X/IR:X/AR:X/MAV:X/MAC:X/MAT:X/MPR:X/MUI:X/MVC:X/MVI:X/MVA:X/MSC:X/MSI:X/MSA:X/S:X/AU:X/R:X/V:X/RE:X/U:X
  • Pear Pearweb

    APP
    Pear
    < 1.33.0
🔵
CHECK WITH VENDOR
No clear patch data available. Check vendor references.
Tags
SQLi
CWE
References

Related vulnerabilities

CVE-2026-25241CRITICAL9.3PL ✓same product

SQL injection w PEAR Pearweb — nieuwierzytelniony dostęp przez endpoint /get/

CVE-2026-25237CRITICAL9.2PL ✓same product

RCE w PEAR Pearweb przez preg_replace() z modyfikatorem /e

CVE-2026-25235HIGH8.2same product

PEAR is a framework and distribution system for reusable PHP components. Prior to version 1.33.0, predictable ...

CVE-2026-25233HIGH7.1same product

PEAR is a framework and distribution system for reusable PHP components. Prior to version 1.33.0, logic bug in...

CVE-2026-25239HIGH8.2same product

PEAR is a framework and distribution system for reusable PHP components. Prior to version 1.33.0, a SQL inject...