SIGB PMB Remote Code Execution Vulnerability via Untrusted File Deserialization

Vulnerability

A remote code execution vulnerability exists in the 'cms_rest.php' component of SIGB PMB version 8.0.1.14. This issue allows attackers to execute arbitrary code by exploiting the application's ability to unserialize data from an arbitrary file, leading to the execution of malicious code on the server.

Impact

Exploitation of this vulnerability allows for remote code execution on the server where SIGB PMB is installed.

Reproduction

To reproduce this vulnerability, send a request to the 'opac_css/cms_rest.php' endpoint with a payload that includes a serialized object containing a file path to a file that can be unserialized. The application will unserialize the file content, and if the file contains executable code, it will be executed on the server.

Remediation

Users are advised to update to the latest version of SIGB PMB where this vulnerability has been addressed.

Added: Nov 25, 2025, 7:21 PM
Updated: Nov 25, 2025, 10:35 PM

Vulnerability Rating

Custom Algorithm
spread
1.0
impact
10.0
exploitability
9.7
remediation
7.7
relevance
1.1
threat
6.4
urgency
2.9
incentive
10.0

Our algorithm analyzes dozens of metrics to generate these 8 key vulnerability categories, which are then combined to calculate the overall risk score.