SIGB PMB
cpe:2.3:a:sigb:pmb:*:*:*:*:*:*:*
- 8.0.1.14
A remote code execution vulnerability exists in the 'cms_rest.php' component of SIGB PMB version 8.0.1.14. This issue allows attackers to execute arbitrary code by exploiting the application's ability to unserialize data from an arbitrary file, leading to the execution of malicious code on the server.
Exploitation of this vulnerability allows for remote code execution on the server where SIGB PMB is installed.
To reproduce this vulnerability, send a request to the 'opac_css/cms_rest.php' endpoint with a payload that includes a serialized object containing a file path to a file that can be unserialized. The application will unserialize the file content, and if the file contains executable code, it will be executed on the server.
Users are advised to update to the latest version of SIGB PMB where this vulnerability has been addressed.
Our algorithm analyzes dozens of metrics to generate these 8 key vulnerability categories, which are then combined to calculate the overall risk score.