PT-2026-26883 · Pbootcms · Pbootcms

Zmjjkk

·

Published

2026-03-21

·

Updated

2026-03-21

·

CVE-2026-4510

CVSS v2.0

5.0

Medium

VectorAV:N/AC:L/Au:N/C:N/I:P/A:N
Name of the Vulnerable Software and Affected Versions PbootCMS versions prior to 3.2.12
Description A weakness exists in PbootCMS that allows for cross site scripting. This issue impacts the alert location function within the apps/home/controller/MemberController.php file, specifically related to the Parameter Handler component. Manipulation of the backurl argument can lead to exploitation. The exploit has been publicly released, potentially enabling attacks.
Recommendations Update PbootCMS to a version newer than 3.2.12. As a temporary workaround, consider restricting access to the alert location function within the apps/home/controller/MemberController.php file until a patch is available.

Exploit

Fix

XSS

Code Injection

Weakness Enumeration

Related Identifiers

CVE-2026-4510

Affected Products

Pbootcms