github.com
https://github.com/jenaye/PMB CVE-2022-34328
MEDIUMNuclei
PMB 7.3.10 - Cross-Site Scripting
Record summary
CVE-2022-34328 has a selected CVSS score of 6.1 (medium); EIP currently links 1 Nuclei template.
Description
PMB 7.3.10 allows reflected XSS via the id parameter in an lvl=author_see request to index.php.
Description source: CVE List
Exploitation context
Available material
- Nuclei templates
- 1
Nuclei templates
1ProjectDiscoveryMEDIUMPMB 7.3.10 - Cross-Site ScriptingCVSS 6.1
PMB 7.3.10 contains a reflected cross-site scripting vulnerability via the id parameter in an lvl=author_see request to index.php.
Impact
Successful exploitation of this vulnerability could allow an attacker to execute malicious scripts in the victim's browser, leading to session hijacking, defacement, or theft of sensitive information.
Remediation
Apply the latest security patch or upgrade to a non-vulnerable version of PMB.
WeaknessesCWE-79
Authorsedoardottt
Template tagscvecve2022pmbxsspmb_projectsigbvuln
CVSS vector: CVSS:3.1/AV:N/AC:L/PR:N/UI:R/S:C/C:L/I:L/A:N
CPE: cpe:2.3:a:sigb:pmb:7.3.10:*:*:*:*:*:*:*
Shodan: http.html:"PMB Group"
Shodan: http.html:"pmb group"
Shodan: http.favicon.hash:1469328760
FOFA: body="pmb group"
FOFA: icon_hash=1469328760
https://github.com/jenaye/PMB/blob/main/README.md https://github.com/jenaye/PMB https://nvd.nist.gov/vuln/detail/CVE-2022-34328 https://github.com/ARPSyndicate/cvemon https://github.com/ARPSyndicate/kenzer-templates
Source: ProjectDiscovery
References
2nvd.nist.gov
https://nvd.nist.gov/vuln/detail/CVE-2022-34328