CVE-2026-30655

SQL injection in Solicitante::resetaSenha() in esiclivre/esiclivre v0.2.2 and earlier allows unauthenticated remote attackers to gain unauthorized access to sensitive information via the cpfcnpj parameter in /reset/index.php
References
Link Resource
https://github.com/brynax/CVE-2026-30655 Mitigation Vendor Advisory
https://github.com/esiclivre/esiclivre Product
Configurations

Configuration 1 (hide)

cpe:2.3:a:esiclivre:esiclivre:*:*:*:*:*:*:*:*

History

No history.

Information

Published : 2026-03-24 15:16

Updated : 2026-03-25 20:53


NVD link : CVE-2026-30655

Mitre link : CVE-2026-30655

CVE.ORG link : CVE-2026-30655


JSON object : View

Products Affected

esiclivre

  • esiclivre
CWE
CWE-89

Improper Neutralization of Special Elements used in an SQL Command ('SQL Injection')