Junglewise Threat Intelligence

CVE-2025-61167: SIGB PMB SQL injection in ajax_selector.php

CVE-2025-61167 · Severity: medium · CVSS 6.5 · Published 2025-11-25

Executive brief

SIGB PMB, a library management system, contains a security vulnerability in its public-facing catalog component. An attacker can exploit this to run unauthorized database commands, potentially leading to the exposure of sensitive library data or unauthorized modifications to the system. This could impact the confidentiality of user records and the integrity of the library's digital catalog.

Technical details

Multiple SQL injection vulnerabilities exist in SIGB PMB v8.0.1.14 within the /opac_css/ajax_selector.php component. The vulnerability is triggered via the 'id' and 'datas' parameters when the 'completion' parameter is set to 'bull_num'. Specifically, the 'id' parameter allows for the insertion of an unescaped single quote, which enables the injection of arbitrary SQL commands through the 'datas' parameter. This is a network-reachable vulnerability that requires no authentication or user interaction. Successful exploitation allows an attacker to read from or modify the underlying database. A fix is referenced in the project's security changelog for version 8.0.1.x.

Affected products

  • SIGB PMB 8.0.1.14

Timeline

  • 2025-11-18: disclosed: Initial discovery/gist creation
  • 2025-11-25: advisory: NVD publication date

References

Related threats