An issue in the cms_rest.php component of SIGB PMB v8.0.1.14 allows attackers to execute arbitrary code via unserializing an arbitrary file.
References
| Link | Resource |
|---|---|
| http://pmb.com | Not Applicable |
| http://sigb.com | Product |
| https://forge.sigb.net/projects/pmb/wiki/Changelog_801#S%C3%A9curit%C3%A9-2 | Release Notes |
| https://gist.github.com/ZanyMonk/446f6875a2ceb3decef5ff1176428f9e | Third Party Advisory |
Configurations
History
No history.
Information
Published : 2025-11-25 19:15
Updated : 2025-12-01 14:21
NVD link : CVE-2025-61168
Mitre link : CVE-2025-61168
CVE.ORG link : CVE-2025-61168
JSON object : View
Products Affected
sigb
- pmb
CWE
CWE-502
Deserialization of Untrusted Data
