Critical severity9.8NVD Advisory· Published Feb 21, 2024· Updated Jun 17, 2026
CVE-2023-37177
CVE-2023-37177
Description
SQL Injection vulnerability in PMB Services PMB v.7.4.7 and before allows a remote unauthenticated attacker to execute arbitrary code via the query parameter in the /admin/convert/export_z3950.php endpoint.
AI Insight
LLM-synthesized narrative grounded in this CVE's description and references.
Affected products
3<=7.4.7+ 1 more
- (no CPE)range: <=7.4.7
- (no CPE)
Patches
Vulnerability mechanics
References
1- nexacybersecurity.blogspot.com/2024/02/journey-finding-vulnerabilities-in-pmb-library-management-system.htmlnvdExploitThird Party Advisory
News mentions
0No linked articles in our index yet.