CVE-2025-0471 - CVE House
Back to Database
Status published Critical CVE-2025-0471

Unrestricted Upload of File with Dangerous Type vulnerability in PMB platform

Vulnerability Description

Unrestricted file upload vulnerability in the PMB platform, affecting versions 4.0.10 and above. This vulnerability could allow an attacker to upload a file to gain remote access to the machine, being able to access, modify and execute commands freely.

Impact Analysis

Refer to official advisory for detailed impact metrics.

Remediation

Ensure systems are updated to the latest vendor-supplied patch levels.

THREAT MONITOR

Am I Vulnerable?

Launch our assessment wizard to check if your infrastructure is exposed to • CVE-2025-0471

Credits & Attribution

The following person or organization is credited with identifying this vulnerability, as recorded in the NVD database:

  • Pau Valls Peleteiro

Affected Vendor

PMB Services

View all reports →

Affected Software

PMB platform
Vulnerable Versions:
4.0.10

Timeline

Official Publish: January 16th, 2025
Last Modified: January 16th, 2025
Added to House: July 22nd, 2026

CVSS Vectors

V3: CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:C/C:H/I:H/A:H

Weaknesses (CWE)