CVE-2026-30655

Publication date

2026-03-24 00:00:00

Family

mitre

State

PUBLISHED

Description

SQL injection in Solicitante::resetaSenha() in esiclivre/esiclivre v0.2.2 and earlier allows unauthenticated remote attackers to gain unauthorized access to sensitive information via the cpfcnpj parameter in /reset/index.php