CVE-2026-25239 | pear pearweb up to 1.32.x filename sql injection (GHSA-f9mg-x463-3vxg)
A vulnerability classified as critical was found in pear pearweb up to 1.32.x. Affected by this issue is some unknown functionality. Executing a manipulation of the argument filename can lead to sql injection.
This vulnerability is tracked as CVE-2026-25239. The attack can be launched remotely. No exploit exists.
Upgrading the affected component is advised.