Executive brief
SIGB PMB, a popular open-source library management system, contains a critical security flaw in its web interface. An attacker can exploit this to take complete control of the server without needing a username or password. This could lead to the theft of sensitive patron data, modification of library records, or a total shutdown of the library's digital services.
Technical details
A remote code execution vulnerability exists in SIGB PMB v8.0.1.14 within the 'opac_css/cms_rest.php' component. The flaw stems from the insecure deserialization (CWE-502) of untrusted data from an arbitrary file. A remote, unauthenticated attacker can trigger this vulnerability by sending a crafted request to the affected endpoint, leading to arbitrary code execution in the context of the web server. While the advisory mentions a fix in the project's security changelog, users should verify they are running a version later than 8.0.1.14.
Affected products
- SIGB PMB 8.0.1.14
Timeline
- 2025-11-18: disclosed: Initial discovery/gist creation
- 2025-11-25: advisory: CVE published to NVD