{"id":"CVE-2026-40455","summary":"SQL Injection in LMS","details":"An SQL Injection vulnerability exists in LMS (LAN Management System) before commit 4cb30a7 within the \"tarifflist.php\" module due to insufficient sanitization of the POST \"tg[]\" parameter. The application directly concatenates user-supplied array values into an SQL query using \"implode()\", allowing authenticated attackers to perform Error-Based SQL injection and extract sensitive database information.","modified":"2026-07-15T01:48:53.163173805Z","published":"2026-06-18T10:58:50.184Z","database_specific":{"osv_generated_from":"https://github.com/CVEProject/cvelistV5/tree/main/cves/2026/40xxx/CVE-2026-40455.json","unresolved_ranges":[{"source":"AFFECTED_FIELD","extracted_events":[{"fixed":"4cb30a7"}]}],"cna_assigner":"CERT-PL","cwe_ids":["CWE-89"]},"references":[{"type":"WEB","url":"https://lms.org.pl/"},{"type":"ADVISORY","url":"https://cert.pl/posts/2026/06/CVE-2026-40455"},{"type":"ADVISORY","url":"https://github.com/CVEProject/cvelistV5/tree/main/cves/2026/40xxx/CVE-2026-40455.json"},{"type":"ADVISORY","url":"https://nvd.nist.gov/vuln/detail/CVE-2026-40455"},{"type":"FIX","url":"https://github.com/chilek/lms/commit/4cb30a70e7e3d8a0ea53afa2dbef19d5243d449b"},{"type":"PACKAGE","url":"https://github.com/chilek/lms"}],"affected":[{"ranges":[{"type":"GIT","repo":"https://github.com/chilek/lms","events":[{"introduced":"0"},{"fixed":"4cb30a70e7e3d8a0ea53afa2dbef19d5243d449b"}],"database_specific":{"source":"REFERENCES"}}],"versions":["LMS_27","LMS_25","LMS_24","LMS_011123","LMS_011122","LMS_011121","LMS_011119","LMS_011118","LMS_011117","LMS_011116","LMS_011115","LMS_011114","X_Dira","X_Aris","X_Bray","X_Kri","LMS_011109","LMS_011108","LMS_011107","LMS_011106","LMS_011105","LMS_011104","LMS_011103","LMS_011102","X_Talus","X_Thoth","X_Idos","LMS_010907","X_Belos","X_Tagar","X_Mot","X_Zarin","X_Thanos","X_Jumar","LMS_010900","X_Grannus","X_Shaq'Ran","X_Wraith","LMS_010703","X_Doci","LMS_010701","LMS_010700","LMS_010506","LMS_010505","LMS_010504","LMS_010503","LMS_010502","LMS_010501","X_Marduk","X_Osiris","X_Ju","X_Terok","X_Sokar","LMS_010302","X_Kinsey","X_Maybourne","X_Apophis","X_Cronos","LMS_010107","X_Seth","LMS_010105","LMS_010104","OLD_FINANCES","LMS_010103","LMS_010102","LMS_010101","LMS_010100","NO_LANGUAGE_SUPPORT","multilanguage","LMS_010000_rc1","LMS_0100_pre10","LMS_0100_pre9","LMS_0100_pre8","LMS_0100_pre7","LMS_0100_pre6","hunter-devel","LMS_0100_pre5","LMS_0100_pre4","LMS_0100_pre3","LMS_0100_pre2","LMS_0100_pre1"],"database_specific":{"source":"https://storage.googleapis.com/cve-osv-conversion/osv-output/CVE-2026-40455.json"}}],"schema_version":"1.7.5","severity":[{"type":"CVSS_V4","score":"CVSS:4.0/AV:A/AC:L/AT:N/PR:L/UI:N/VC:H/VI:H/VA:L/SC:N/SI:N/SA:N"}]}