Executive brief
Pixa Bank, a banking application, contains a security flaw that allows unauthorized individuals to access its internal database. By sending specially crafted requests to the application, an attacker can steal sensitive customer information such as names, email addresses, and phone numbers. This could lead to significant data privacy breaches and identity theft risks for the bank's customers.
Technical details
An SQL injection vulnerability exists in Pixa Bank version 2.0 and earlier within the 'rib' parameter of the agence-ajax.php endpoint. The flaw is caused by improper neutralization of special elements used in an SQL command (CWE-89). An unauthenticated remote attacker can exploit this by sending a POST request containing UNION-based SQL payloads. Successful exploitation allows the attacker to bypass authentication and perform arbitrary database queries, leading to the exfiltration of sensitive user data including names, emails, and phone numbers. No user interaction is required for exploitation.
Affected products
- Pixa Studio Pixa Bank 2.0 and earlier
Timeline
- 2026-06-01: disclosed
- 2026-06-01: advisory