Show filters
17 Total Results
Displaying 1-10 of 17
Sort by:
Attacker Value
Unknown

CVE-2025-0473

Disclosure Date: January 16, 2025 (last updated January 17, 2025)
Vulnerability in the PMB platform that allows an attacker to persist temporary files on the server, affecting versions 4.0.10 and above. This vulnerability exists in the file upload functionality on the ‘/pmb/authorities/import/iimport_authorities’ endpoint. When a file is uploaded via this resource, the server will create a temporary file that will be deleted after the client sends a POST request to ‘/pmb/authorities/import/iimport_authorities’. This workflow is automated by the web client, however an attacker can trap and launch the second POST request to prevent the temporary file from being deleted.
0
Attacker Value
Unknown

CVE-2025-0472

Disclosure Date: January 16, 2025 (last updated January 17, 2025)
Information exposure in the PMB platform affecting versions 4.2.13 and earlier. This vulnerability allows an attacker to upload a file to the environment and enumerate the internal files of a machine by looking at the request response.
0
Attacker Value
Unknown

CVE-2025-0471

Disclosure Date: January 16, 2025 (last updated January 17, 2025)
Unrestricted file upload vulnerability in the PMB platform, affecting versions 4.0.10 and above. This vulnerability could allow an attacker to upload a file to gain remote access to the machine, being able to access, modify and execute commands freely.
0
Attacker Value
Unknown

CVE-2024-26289

Disclosure Date: May 27, 2024 (last updated May 27, 2024)
Deserialization of Untrusted Data vulnerability in PMB Services PMB allows Remote Code Inclusion.This issue affects PMB: from 7.5.1 before 7.5.6-2, from 7.4.1 before 7.4.9, from 7.3.1 before 7.3.18.
0
Attacker Value
Unknown

CVE-2023-46474

Disclosure Date: January 11, 2024 (last updated January 19, 2024)
File Upload vulnerability PMB v.7.4.8 allows a remote attacker to execute arbitrary code and escalate privileges via a crafted PHP file uploaded to the start_import.php file.
Attacker Value
Unknown

CVE-2023-24737

Disclosure Date: March 06, 2023 (last updated February 24, 2025)
PMB v7.4.6 was discovered to contain a reflected cross-site scripting (XSS) vulnerability via the query parameter at /admin/convert/export_z3950.php.
Attacker Value
Unknown

CVE-2023-24736

Disclosure Date: March 06, 2023 (last updated January 19, 2024)
PMB v7.4.6 was discovered to contain a remote code execution (RCE) vulnerability via the component /sauvegarde/restaure_act.php.
Attacker Value
Unknown

CVE-2023-24735

Disclosure Date: March 06, 2023 (last updated February 24, 2025)
PMB v7.4.6 was discovered to contain an open redirect vulnerability via the component /opac_css/pmb.php. This vulnerability allows attackers to redirect victim users to an external domain via a crafted URL.
Attacker Value
Unknown

CVE-2023-24734

Disclosure Date: March 06, 2023 (last updated February 24, 2025)
An arbitrary file upload vulnerability in the camera_upload.php component of PMB v7.4.6 allows attackers to execute arbitrary code via a crafted image file.
Attacker Value
Unknown

CVE-2023-24733

Disclosure Date: March 06, 2023 (last updated February 24, 2025)
PMB v7.4.6 was discovered to contain a reflected cross-site scripting (XSS) vulnerability via the query parameter at /admin/convert/export_z3950_new.php.