CVE-2025-0473

CVSS 3.1 Score 6.5 of 10 (medium)

Details

Published Jan 16, 2025
CWE ID 459

Summary

CVE-2025-0473 is a vulnerability affecting versions 4.0.10 and above of the PMB platform. It allows attackers to persist temporary files on the server by interfering with the automated file deletion process. The issue lies in the file upload functionality of the ‘/pmb/authorities/import/iimport_authorities’ endpoint. Upon uploading a file, the server creates a temporary file which is intended to be deleted after the client sends a POST request. However, an attacker can manipulate this process by preventing the second POST request, thereby keeping the temporary file on the server.

Ligh bulbPrevent cyber attacks with Recorded Future by prioritizing and patching critical vulnerabilities being exploited by threat actors targeting your industry. Book your demo to learn more.

Share