Phying News
Curated security research, vulnerabilities, advisories and tools for practitioners.

[CVE-2026-44886] Pi.Alert - Unauthenticated SQL Injection

Summary

Pi.Alert has an unauthenticated SQL injection (CVE-2026-44886): an unsanitised scansource parameter lets attackers dump the whole database. Covers the code flow and a sqlmap proof of concept.
Published
Collected

original ↗

Related coverage

back