CVE-2022-34328
18Vexday Risk Score
Patch soon. It has a working public exploit.
ssvc Attendepss 2.2%
exploitation probability
2.2%top 20% of all CVEs
observed exploitation
nono source reports it
PMB 7.3.10 allows reflected XSS via the id parameter in an lvl=author_see request to index.php.
Affected products
n/a · n/aReferences
https://github.com/jenaye/PMB