File Upload Vulnerability in PMB Platform Affects Multiple Versions
CVE-2025-0473
7.5HIGH
What is CVE-2025-0473?
The PMB platform is susceptible to a file upload vulnerability that allows an attacker to persist temporary files on the server. This issue arises at the '/pmb/authorities/import/iimport_authorities' endpoint, where a malicious user can disrupt the automated deletion of temporary files. By intercepting and manipulating the POST request that follows a file upload, an attacker can exploit this flaw to retain sensitive information on the server, potentially leading to further security breaches.
Affected Version(s)
PMB platform 4.0.10