PT-2021-17830 · Pbootcms · Pbootcms

M40K1N9

·

Published

2021-03-31

·

Updated

2021-04-05

·

CVE-2021-28245

CVSS v3.1

7.5

High

VectorAV:N/AC:L/PR:N/UI:N/S:U/C:H/I:N/A:N
Name of the Vulnerable Software and Affected Versions: PbootCMS version 3.0.4
Description: The issue allows for SQL injection through the search parameter in index.php, potentially revealing sensitive information and enabling the addition of an admin account.
Recommendations: For PbootCMS version 3.0.4, consider restricting access to the index.php endpoint until a patch is available, and avoid using the search parameter to minimize the risk of exploitation.

Exploit

Fix

SQL injection

Found an issue in the description? Have something to add? Feel free to write us 👾

Weakness Enumeration

Related Identifiers

CVE-2021-28245

Affected Products

Pbootcms