PT-2026-26887 · Pbootcms · Pbootcms
Zmjjkk
·
Published
2026-03-21
·
Updated
2026-03-22
·
CVE-2026-4514
CVSS v2.0
6.5
Medium
| Vector | AV:N/AC:L/Au:S/C:P/I:P/A:P |
Name of the Vulnerable Software and Affected Versions
PbootCMS versions up to 3.2.12
Description
A flaw exists in PbootCMS that may allow for improper access controls. This issue is related to functionality within the
apps/admin/controller/system/UserController.php file of the Backend component. Exploitation involves manipulating the Field argument, and the attack can be performed remotely. The exploit has been published.Recommendations
Versions prior to 3.2.12 are affected. At the moment, there is no information about a newer version that contains a fix for this vulnerability.
Exploit
Incorrect Privilege Assignment
Improper Access Control
Found an issue in the description? Have something to add? Feel free to write us 👾
Related Identifiers
Affected Products
Pbootcms