CVE-2026-25241 | pear pearweb up to 1.32.x /get// sql injection (GHSA-63fv-vpq5-gv8p)
A vulnerability described as critical has been identified in pear pearweb up to 1.32.x. Affected is an unknown function of the file /get//. Such manipulation leads to sql injection.
This vulnerability is referenced as CVE-2026-25241. It is possible to launch the attack remotely. No exploit is available.
Upgrading the affected component is recommended.