S4E just found a high-severity finding from top 10 tcp port service scan
PlatformPlansPartners
Resources
ToolsBlogDocs
Sign Up →
medium·Product Based Web Vulnerabilities·Updated Jan 3, 2024

CVE-2022-34328 Scanner

CVE-2022-34328 scanner - Cross-Site Scripting (XSS) vulnerability in PMB

Est. Time~10 seconds
Scan TypeSingle Scan
Targetsurl
CostFree
3.1k
Times Used
continuous scan runs
4.7k
Continuously Checked
assets under CS
0
Vulnerabilities Found
confirmed findings
References
CVECVE-2022-34328
6.1
CVSS

PMB 7.3.10 allows reflected XSS via the id parameter in an lvl=author_see request to index.php.

Attack Vector
-
Privileges Req.
-
User Interaction
-
Affected
n/aby n/a
n/a
Updated Aug 22, 2026View on NVD →
Detail

PMB, short for "PhpMyBibli", is an open-source bibliographic software used by libraries and research institutions worldwide for cataloging and maintaining their bibliographic data. PMB serves as an essential tool for managing research outputs, bibliographic metadata, and library collections. The software offers an easy-to-use interface for managing various bibliographic and multimedia resources, including books, journals, videos, and images. PMB helps in managing end-to-end library operations, from acquisition to cataloging, lending, and circulation.

CVE-2022-34328 is a vulnerability that researchers recently detected in PMB 7.3.10. This vulnerability is caused by an inadequate sanitization of the input data to the id parameter in an lvl=author_see request to index.php, which can lead to a reflected XSS attack. This means that an attacker can make use of this vulnerability to inject malicious code into a web page, leading to the theft of sensitive data and a successful security breach.

If exploited, CVE-2022-34328 could cause significant damage to organizations that rely on PMB for their bibliographic data management. Attackers can exploit this vulnerability to gain access to sensitive information, including usernames, passwords, credit card information, and other critical data stored in the library systems. This vulnerability could also compromise the integrity of the system, leading to downtimes, system crashes, or loss of data.

Organizations must take proactive measures to protect their digital assets against vulnerabilities in their software. The s4e.io platform provides comprehensive security solutions that help organizations identify and mitigate security risks and vulnerabilities in real-time. By utilizing the pro features of the platform, organizations can stay ahead of potential security breaches and protect their systems and data from exploitation. Stay secure with s4e.io!

 

REFERENCES

Solution Advice

Organizations using PMB can take proactive measures to protect their systems against this vulnerability. The following precautions can be taken:

  • Regularly update the PMB software to the latest version.
  • Deploy web application firewalls that can detect XSS attacks in real-time and prevent them from entering your system.
  • Implement code validations, such as input sanitization, to ensure that untrusted data is not processed in your application.
  • Educate system administrators and users about the potential risks of XSS attacks and how to prevent them.
  • Use strong and unique passwords and multi-factor authentication to prevent unauthorized access to the system.

Get AI-powered remediation steps tailored to your asset.

Try AI Solutions →

Check your infrastructure.
Right now.

11,000+ scanners. Free to start. No credit card required.