PT-2022-22133 · Pmb · Pmb

Published

2022-06-22

·

Updated

2024-01-18

·

CVE-2022-34328

CVSS v3.1

6.1

Medium

VectorAV:N/AC:L/PR:N/UI:R/S:C/C:L/I:L/A:N
Name of the Vulnerable Software and Affected Versions PMB version 7.3.10
Description The issue allows reflected XSS via the id parameter in an lvl=author see request to "index.php". This can potentially lead to malicious script execution.
Recommendations For PMB version 7.3.10, consider restricting access to the id parameter in the "index.php" endpoint to minimize the risk of exploitation. As a temporary workaround, avoid using the id parameter in requests with lvl=author see until a patch is available. At the moment, there is no information about a newer version that contains a fix for this vulnerability.

Exploit

XSS

Weakness Enumeration

Related Identifiers

CVE-2022-34328

Affected Products

Pmb