Record summary

CVE-2022-34328 has a selected CVSS score of 6.1 (medium); EIP currently links 1 Nuclei template.

Description

PMB 7.3.10 allows reflected XSS via the id parameter in an lvl=author_see request to index.php.

Description source: CVE List

Exploitation context

Available material

Nuclei templates
1

Nuclei templates

1
ProjectDiscoveryMEDIUMPMB 7.3.10 - Cross-Site ScriptingCVSS 6.1

PMB 7.3.10 contains a reflected cross-site scripting vulnerability via the id parameter in an lvl=author_see request to index.php.

Impact

Successful exploitation of this vulnerability could allow an attacker to execute malicious scripts in the victim's browser, leading to session hijacking, defacement, or theft of sensitive information.

Remediation

Apply the latest security patch or upgrade to a non-vulnerable version of PMB.

WeaknessesCWE-79
Authorsedoardottt
Template tagscvecve2022pmbxsspmb_projectsigbvuln
CVSS vector: CVSS:3.1/AV:N/AC:L/PR:N/UI:R/S:C/C:L/I:L/A:N
CPE: cpe:2.3:a:sigb:pmb:7.3.10:*:*:*:*:*:*:*
Shodan: http.html:"PMB Group"
Shodan: http.html:"pmb group"
Shodan: http.favicon.hash:1469328760
FOFA: body="pmb group"
FOFA: icon_hash=1469328760

Source: ProjectDiscovery

References

2