File Upload Vulnerability in PMB Platform Affects Multiple Versions
CVE-2025-0473
7.5HIGH
What is CVE-2025-0473?
The PMB platform is susceptible to a file upload vulnerability that allows an attacker to persist temporary files on the server. This issue arises at the '/pmb/authorities/import/iimport_authorities' endpoint, where a malicious user can disrupt the automated deletion of temporary files. By intercepting and manipulating the POST request that follows a file upload, an attacker can exploit this flaw to retain sensitive information on the server, potentially leading to further security breaches.

Human OS v1.0:
Ageing Is an Unpatched Zero-Day Vulnerability.
Remediate biological technical debt. Prime Ageing uses 95% high-purity SIRT6 activation to maintain genomic integrity and bolster systemic resilience.
Affected Version(s)
PMB platform 4.0.10
References
CVSS V3.1
Score:
7.5
Severity:
HIGH
Confidentiality:
High
Integrity:
None
Availability:
High
Attack Vector:
Network
Attack Complexity:
Low
Privileges Required:
None
User Interaction:
None
Scope:
Unchanged
Timeline
Vulnerability published
Vulnerability Reserved
Credit
Pau Valls Peleteiro
