PEAR is a framework and distribution system for reusable PHP components. Prior to version 1.33.0, a SQL injection vulnerability in bug subscription deletion may allow attackers to inject SQL via a crafted email value. This issue has been patched in version 1.33.0.
The vulnerability results from the lack of proper validation and parameterization of user input passed in the email address field during the bug subscription deletion operation. An attacker can provide a crafted email value containing malicious SQL code fragments, which will be directly included in the executed database query. This technique allows manipulation of the logic of SQL queries executed by the application.
Successful exploitation of this vulnerability may allow an attacker to perform unauthorized read, modification, or deletion of data stored in the PEAR Pearweb application database. Depending on the database configuration, it is also possible to escalate the attack to further infrastructure layers.
PEAR Pearweb should be updated to version 1.33.0 or later, in which the vulnerability has been patched. Detailed information is available in the vendor's references at: https://github.com/pear/pearweb/security/advisories/GHSA-cv3c-27h5-7gmv
PEAR Pearweb versions prior to 1.33.0
CVSS:4.0/AV:N/AC:L/AT:P/PR:N/UI:N/VC:H/VI:H/VA:H/SC:N/SI:N/SA:N/E:X/CR:X/IR:X/AR:X/MAV:X/MAC:X/MAT:X/MPR:X/MUI:X/MVC:X/MVI:X/MVA:X/MSC:X/MSI:X/MSA:X/S:X/AU:X/R:X/V:X/RE:X/U:XPear Pearweb
APPPear< 1.33.0
Related vulnerabilities
SQL injection w PEAR Pearweb — nieuwierzytelniony dostęp przez endpoint /get/
RCE w PEAR Pearweb przez preg_replace() z modyfikatorem /e
PEAR is a framework and distribution system for reusable PHP components. Prior to version 1.33.0, predictable ...
PEAR is a framework and distribution system for reusable PHP components. Prior to version 1.33.0, logic bug in...
PEAR is a framework and distribution system for reusable PHP components. Prior to version 1.33.0, a SQL inject...