S4E just found a high-severity finding from top 10 tcp port service scan
PlatformPlansPartners
Resources
ToolsBlogDocs
Sign Up →
medium·Product Based Web Vulnerabilities·Updated Jan 3, 2024

CVE-2023-24737 Scanner

Detects 'Cross-Site Scripting (XSS)' vulnerability in PMB affects v. 7.4.6.

Est. Time~10 seconds
Scan TypeSingle Scan
Targetsdomain, ipv4, subdomain
CostFree
3k
Times Used
continuous scan runs
5.8k
Continuously Checked
assets under CS
3
Vulnerabilities Found
confirmed findings
References
CVECVE-2023-24737
6.1
CVSS

PMB v7.4.6 was discovered to contain a reflected cross-site scripting (XSS) vulnerability via the query parameter at /admin/convert/export_z3950.php.

Attack Vector
-
Privileges Req.
-
User Interaction
-
Affected
n/aby n/a
n/a
Updated Aug 22, 2026View on NVD →
Detail

PMB, which stands for "Integrated Library System," is an open-source software used to manage library collections, circulation of materials, and cataloging of items. It provides tools to support acquisition, cataloging, and circulation of library resources, and can be customized to fit the needs of individual libraries. The system is popular among small-sized libraries and educational institutions as it offers various features that help manage library resources effectively while also providing seamless accessibility to library patrons.

Recently, a vulnerability was discovered in PMB, which affects version 7.4.6. The vulnerability has been identified as reflected cross-site scripting (XSS), and it can be exploited through the query parameter at /admin/convert/export_z3950.php. This vulnerability enabled attackers to inject scripts into web pages viewed by other users. These scripts can then steal sensitive information from users such as passwords, session tokens, or credit card details.

Exploiting this vulnerability can lead to various consequences that pose significant risks to libraries and their patrons. For instance, cybercriminals can inject malicious code that could redirect users to phishing sites or download malware on their computers. Attackers can also launch attacks to steal authentication credentials, which, when successful, can give them access to the internal networks of libraries, where sensitive library records and user data are stored.

In conclusion, protecting digital assets is crucial in the modern era of 21st-century cybersecurity. s4e.io offers a platform that features the latest technologies to help individuals and businesses secure their digital assets. By using the platform, libraries and their IT departments can easily and quickly identify vulnerabilities in their digital assets and prevent potential cyber-attacks before they become a significant risk.

 

REFERENCES

Solution Advice

To protect against this vulnerability, there are a couple of mitigation techniques that libraries and their IT departments can take. These include:

  • Applying updates and patches promptly: System administrators should keep their systems updated with the latest security patches and fixes, as they often contain solutions to identified vulnerabilities, including those found in PMB.
  • Implementing filters: Libraries can apply filters to validate user input, such as encoding and decoding scripts, to prevent attackers from injecting malicious code into web pages.
  • Training staff and library patrons: Security awareness training can help library staff and users recognize common scams, such as phishing attacks that often target libraries, to prevent cyber-attacks.

Get AI-powered remediation steps tailored to your asset.

Try AI Solutions →

Check your infrastructure.
Right now.

11,000+ scanners. Free to start. No credit card required.

CVE-2023-24737 scanner - Cross-Site Scripting (XSS) vulnerability in PMB | S4E