CVE-2025-0472

Information exposure in the PMB platform affecting versions 4.2.13 and earlier. This vulnerability allows an attacker to upload a file to the environment and enumerate the internal files of a machine by looking at the request response.
Configurations

Configuration 1 (hide)

cpe:2.3:a:sigb:pmb:*:*:*:*:*:*:*:*

History

07 May 2025, 16:24

Type Values Removed Values Added
Summary
  • (es) Exposición de información en la plataforma PMB que afecta a las versiones 4.2.13 y anteriores. Esta vulnerabilidad permite a un atacante cargar un archivo al entorno y enumerar los archivos internos de una máquina observando la respuesta de la solicitud.
First Time Sigb pmb
Sigb
References () https://www.incibe.es/en/incibe-cert/notices/aviso/multiple-vulnerabilities-pmb-platform - () https://www.incibe.es/en/incibe-cert/notices/aviso/multiple-vulnerabilities-pmb-platform - Third Party Advisory
CPE cpe:2.3:a:sigb:pmb:*:*:*:*:*:*:*:*
CWE CWE-434

16 Jan 2025, 13:15

Type Values Removed Values Added
New CVE

Information

Published : 2025-01-16 13:15

Updated : 2025-05-07 16:24


NVD link : CVE-2025-0472

Mitre link : CVE-2025-0472

CVE.ORG link : CVE-2025-0472


JSON object : View

Products Affected

sigb

  • pmb
CWE
CWE-200

Exposure of Sensitive Information to an Unauthorized Actor

CWE-434

Unrestricted Upload of File with Dangerous Type