NA

CVE-2023-46474

Published: 11/01/2024 Updated: 18/01/2024
CVSS v3 Base Score: 7.2 | Impact Score: 5.9 | Exploitability Score: 1.2
VMScore: 0

Vulnerability Summary

File Upload vulnerability PMB v.7.4.8 allows a remote malicious user to execute arbitrary code and escalate privileges via a crafted PHP file uploaded to the start_import.php file.

Vulnerable Product Search on Vulmon Subscribe to Product

sigb pmb

Vendor Advisories

Check Point Reference: CPAI-2023-1752 Date Published: 9 Jun 2024 Severity: High ...

Github Repositories

Technical details for CVE-2023-46474

PMB <=753 - Remote Code Execution via Unrestricted File Upload CVE-2023-46474 CVSS v31 Vector CVSS v31 Score AV:N/AC:L/PR:H/UI:N/S:C/C:H/I:H/A:H 91 Découverte dans le cadre d'un test d'intrusion par Marcus Reynaud de Devensys Cybersecurity Description Le script pmb/admin/convert/start_importphp est vulnérable à une faille de