ID:12931 - Exploit for SQL injection in PHP - CVE-2026-17543

 
Main Vulnerability Database Exploits ID:12931 - Exploit for SQL injection in PHP - CVE-2026-17543

ID:12931 - Exploit for SQL injection in PHP - CVE-2026-17543

Published: August 14, 2026


Vulnerability identifier: #VU140832
Vulnerability risk: High
CVE-ID: CVE-2026-17543
CWE-ID: CWE-89
Exploitation vector: Remote access
Vulnerable software:
PHP
Debian Linux
SUSE Linux Enterprise Server 15 SP6
SUSE Linux Enterprise Server 15 SP5
SUSE Linux Enterprise Server 15 SP4
SUSE Linux Enterprise High Performance Computing 15
SUSE Linux Enterprise High Performance Computing ESPOS 15
SUSE Linux Enterprise Server for SAP Applications 15
SUSE Linux Enterprise High Performance Computing LTSS 15
SUSE Linux Enterprise Server 15
SUSE Linux Enterprise Real Time 15
SUSE Linux Enterprise Desktop 15
SUSE Package Hub 15
Legacy Module
Web and Scripting Module
openSUSE Leap
Fedora
php7-fileinfo-debuginfo
php7-dom-debuginfo
php7-readline
php7-pdo-debuginfo
php7-zlib
php7-posix
php7-gettext-debuginfo
php7-sodium-debuginfo
php7-xmlwriter
php7-phar
php7-bcmath-debuginfo
apache2-mod_php7-debuginfo
php7
php7-zip-debuginfo
php7-xmlrpc-debuginfo
php7-odbc
php7-sqlite-debuginfo
php7-ldap-debuginfo
php7-ftp
php7-devel
apache2-mod_php7
php7-ctype
apache2-mod_php7-debugsource
php7-mbstring
php7-shmop-debuginfo
php7-xmlwriter-debuginfo
php7-openssl
php7-exif
php7-fastcgi-debugsource
php7-pcntl
php7-opcache
php7-sysvsem
php7-dba
php7-fpm-debugsource
php7-pgsql-debuginfo
php7-gmp-debuginfo
php7-intl
php7-sodium
php7-cli
php7-calendar
php7-xsl-debuginfo
php7-sqlite
php7-json-debuginfo
php7-iconv
php7-bcmath
php7-fpm-debuginfo
php7-mbstring-debuginfo
php7-bz2-debuginfo
php7-enchant-debuginfo
php7-gettext
php7-iconv-debuginfo
php7-calendar-debuginfo
php7-zip
php7-snmp-debuginfo
php7-xmlreader
php7-sockets-debuginfo
php7-ctype-debuginfo
php7-ldap
php7-xmlreader-debuginfo
php7-fastcgi
php7-sysvshm-debuginfo
php7-tidy
php7-debugsource
php7-sysvmsg
php7-soap
php7-sockets
php7-mysql-debuginfo
php7-zlib-debuginfo
php7-json
php7-cli-debuginfo
php7-ftp-debuginfo
php7-gd-debuginfo
php7-xmlrpc
php7-exif-debuginfo
php7-curl
php7-opcache-debuginfo
php7-fileinfo
php7-odbc-debuginfo
php7-fpm
php7-shmop
php7-readline-debuginfo
php7-embed-debugsource
php7-dba-debuginfo
php7-tokenizer-debuginfo
php7-openssl-debuginfo
php7-curl-debuginfo
php7-tokenizer
php7-soap-debuginfo
php7-gd
php7-sysvshm
php7-posix-debuginfo
php7-snmp
php7-fastcgi-debuginfo
php7-pgsql
php7-dom
php7-pcntl-debuginfo
php7-embed
php7-sysvsem-debuginfo
php7-bz2
php7-pdo
php7-intl-debuginfo
php7-sysvmsg-debuginfo
php7-xsl
php7-mysql
php7-phar-debuginfo
php7-tidy-debuginfo
php7-debuginfo
php7-gmp
php7-enchant
php7-embed-debuginfo
php7-test
php8-tidy-debuginfo
php8-xmlwriter
php8-ftp-debuginfo
php8-xmlwriter-debuginfo
php8-ldap
php8-tokenizer
php8-cli
php8-posix-debuginfo
php8-debugsource
php8-cli-debuginfo
php8-devel
php8-bz2
php8-opcache-debuginfo
php8-sysvshm-debuginfo
php8-mbstring-debuginfo
php8-shmop-debuginfo
php8-zlib-debuginfo
php8-tidy
php8-tokenizer-debuginfo
php8-fpm
php8-enchant-debuginfo
php8-openssl
php8-opcache
php8-xsl
php8-dom
php8-xmlreader
php8-odbc
php8-gettext-debuginfo
php8-embed
php8-gd-debuginfo
php8-shmop
php8-exif
php8-openssl-debuginfo
php8-pgsql-debuginfo
php8-snmp-debuginfo
php8-intl
php8-pdo
php8-embed-debuginfo
php8-zlib
php8-bcmath-debuginfo
php8-fileinfo-debuginfo
php8-curl
php8-posix
php8-soap-debuginfo
php8-odbc-debuginfo
php8-sysvsem-debuginfo
php8-intl-debuginfo
php8-gd
php8-calendar-debuginfo
php8-gmp
php8-calendar
php8-sysvmsg-debuginfo
php8-gettext
php8-xmlreader-debuginfo
php8-mysql
php8-embed-debugsource
php8-exif-debuginfo
php8-ctype-debuginfo
php8-test
php8-dba-debuginfo
php8-sodium
php8-enchant
php8-fpm-debuginfo
php8-pdo-debuginfo
php8-xsl-debuginfo
php8-pgsql
php8-soap
php8-ftp
php8-mbstring
php8-gmp-debuginfo
php8-pcntl
php8-ldap-debuginfo
php8-dba
php8-sysvsem
php8-bz2-debuginfo
php8-sqlite-debuginfo
php8-fpm-debugsource
php8-fastcgi-debugsource
php8-snmp
php8-sysvshm
php8-sodium-debuginfo
php8-iconv-debuginfo
php8-sysvmsg
php8-debuginfo
php8-fileinfo
php8-readline-debuginfo
php8-fastcgi-debuginfo
php8-mysql-debuginfo
apache2-mod_php8-debugsource
php8-dom-debuginfo
php8-phar-debuginfo
php8-ctype
php8-sockets
apache2-mod_php8
php8-phar
php8-zip-debuginfo
php8-iconv
php8-zip
php8-fastcgi
php8-sockets-debuginfo
php8-readline
apache2-mod_php8-debuginfo
php8-curl-debuginfo
php8
php8-sqlite
php8-bcmath
php8-pcntl-debuginfo
php8-fpm-apache
php8-ffi
php8-ffi-debuginfo
php
php8.4 (Debian package)

Link to public exploit:


Vulnerability description

The vulnerability allows a remote attacker to execute arbitrary SQL queries in database.

The vulnerability exists due to insufficient sanitization of user-supplied data in ext-pgsql extension. A remote attacker can send a specially crafted request to the affected application and execute arbitrary SQL commands within the application database.


Remediation

Install updates from vendor's website.