PT-2026-26883 · Pbootcms · Pbootcms

Zmjjkk

·

Publicado

2026-03-21

·

Atualizado

2026-03-21

·

CVE-2026-4510

CVSS v2.0

5.0

Média

VetorAV:N/AC:L/Au:N/C:N/I:P/A:N
Name of the Vulnerable Software and Affected Versions PbootCMS versions prior to 3.2.12
Description A weakness exists in PbootCMS that allows for cross site scripting. This issue impacts the alert location function within the apps/home/controller/MemberController.php file, specifically related to the Parameter Handler component. Manipulation of the backurl argument can lead to exploitation. The exploit has been publicly released, potentially enabling attacks.
Recommendations Update PbootCMS to a version newer than 3.2.12. As a temporary workaround, consider restricting access to the alert location function within the apps/home/controller/MemberController.php file until a patch is available.

Exploit

Correção

XSS

Code Injection

Encontrou algum problema na descrição? Tem algo a acrescentar? Fique à vontade para nos escrever 👾

Enumeração de Fraquezas

Identificadores relacionados

CVE-2026-4510

Produtos afetados

Pbootcms