
Security advisory for CVE-2026-30655: unauthenticated SQL injection in esiclivre (/reset/index.php).
A SQL injection vulnerability exists in the password reset endpoint of esiclivre. An unauthenticated attacker can inject SQL via the cpfcnpj POST parameter, potentially resulting in unauthorized access to sensitive information.
POST /reset/index.phpcpfcnpjSolicitante::resetaSenha() without parameterization.No upstream fix is available at the time of publication. Recommended remediation:
Discovered by Bryan Romero (https://github.com/brynax).