Junglewise Threat Intelligence

CVE-2025-61168: SIGB PMB remote code execution in cms_rest.php

CVE-2025-61168 · Severity: critical · CVSS 9.8 · Published 2025-11-25

Executive brief

SIGB PMB, a popular open-source library management system, contains a critical security flaw in its web interface. An attacker can exploit this to take complete control of the server without needing a username or password. This could lead to the theft of sensitive patron data, modification of library records, or a total shutdown of the library's digital services.

Technical details

A remote code execution vulnerability exists in SIGB PMB v8.0.1.14 within the 'opac_css/cms_rest.php' component. The flaw stems from the insecure deserialization (CWE-502) of untrusted data from an arbitrary file. A remote, unauthenticated attacker can trigger this vulnerability by sending a crafted request to the affected endpoint, leading to arbitrary code execution in the context of the web server. While the advisory mentions a fix in the project's security changelog, users should verify they are running a version later than 8.0.1.14.

Affected products

  • SIGB PMB 8.0.1.14

Timeline

  • 2025-11-18: disclosed: Initial discovery/gist creation
  • 2025-11-25: advisory: CVE published to NVD

References

Related threats