CRITICAL🇵🇱 Wersja polska

CVE-2026-25241

CVSS 9.3v4.0pub. 2026-02-03upd. 2026-02-05

PEAR is a framework and distribution system for reusable PHP components. Prior to version 1.33.0, an unauthenticated SQL injection in the /get/<package>/<version> endpoint allows remote attackers to execute arbitrary SQL via a crafted package version. This issue has been patched in version 1.33.0.

🤖 AI Analysis
How it works

An attacker sends a crafted HTTP request to the /get/<package>/<version> endpoint, injecting malicious SQL code in the package version parameter. The application does not validate or sanitize this parameter before using it in a database query. As a result, an attacker can manipulate SQL query logic without needing to have any account or session in the system.

Impact

An attacker can read, modify, or delete data stored in the application's database, which may lead to disclosure of sensitive information and violation of data integrity.

Mitigation & patch

PEAR Pearweb should be updated to version 1.33.0, in which the vulnerability has been fixed. Details are available in the vendor's references on GitHub Security Advisory GHSA-63fv-vpq5-gv8p.

Who is affected

PEAR Pearweb in versions before 1.33.0

Analysis generated by Claude AI (Anthropic) based on NVD data. Always verify with vendor.
CVSS Vector
CVSS:4.0/AV:N/AC:L/AT:N/PR:N/UI:N/VC:H/VI:H/VA:H/SC:N/SI:N/SA:N/E:X/CR:X/IR:X/AR:X/MAV:X/MAC:X/MAT:X/MPR:X/MUI:X/MVC:X/MVI:X/MVA:X/MSC:X/MSI:X/MSA:X/S:X/AU:X/R:X/V:X/RE:X/U:X
  • Pear Pearweb

    APP
    Pear
    < 1.33.0
🔵
CHECK WITH VENDOR
No clear patch data available. Check vendor references.
Tags
SQLi
CWE
References

Related vulnerabilities

CVE-2026-25238CRITICAL9.2PL ✓same product

SQL Injection w PEAR Pearweb — podatność przy usuwaniu subskrypcji błędów

CVE-2026-25237CRITICAL9.2PL ✓same product

RCE w PEAR Pearweb przez preg_replace() z modyfikatorem /e

CVE-2026-25233HIGH7.1same product

PEAR is a framework and distribution system for reusable PHP components. Prior to version 1.33.0, logic bug in...

CVE-2026-25235HIGH8.2same product

PEAR is a framework and distribution system for reusable PHP components. Prior to version 1.33.0, predictable ...

CVE-2026-25239HIGH8.2same product

PEAR is a framework and distribution system for reusable PHP components. Prior to version 1.33.0, a SQL inject...