1.
projectblack.io | research | | original ↗ | #vulnerability-research | #sql-injection | #vulnerability-disclosure | #pi-alert
Pi.Alert has an unauthenticated SQL injection (CVE-2026-44886): an unsanitised scansource parameter lets attackers dump the whole database. Covers the code flow and a sqlmap proof of concept.
Skip to content