CyberRota Analysis
This is a critical severity vulnerability with a CVSS score of 9.8. It may be remotely exploitable. It involves a SQL injection risk. Exploitation may require the attacker to be authenticated.
CVE
CVE-2023-37177
Severity
CRITICAL
CVSS
9.8
EPSS
1.12%
Original NVD Description
SQL Injection vulnerability in PMB Services PMB v.7.4.7 and before allows a remote unauthenticated attacker to execute arbitrary code via the query parameter in the /admin/convert/export_z3950.php endpoint.
Related CVEs
Other vulnerabilities affecting the same vendor(s)