Impact
The Pi.Alert web interface processes the scansource parameter without adequate validation, enabling unauthenticated blind SQL injection via the devices.php endpoint. This flaw falls under CWE-89 and could allow attackers to retrieve or alter database contents, compromising confidentiality and integrity of network device data.
Affected Systems
Pi.Alert, developed by leiweibau, all releases prior to and including 2026-05-07 are affected. The vulnerability exists from 2024-06-29 until the patch released on 2026-05-07.
Risk and Exploitability
The CVSS score of 8.7 indicates high severity. EPSS is not available, so we cannot quantify the current exploitation probability, and the vulnerability is not catalogued in CISA KEV. Based on the description, the likely attack vector is an unauthenticated HTTP request to /pialert/php/server/devices.php with the action set to getDevicesTotals and a crafted scansource value. An attacker with network access can exploit this flaw remotely to query the database and extract or modify sensitive data.
OpenCVE Enrichment