SQL Injection vulnerability in PbootCMS 1.4.1 in parsing if statements in templates, resulting in a malicious user's ability to contaminate template content by searching for page contamination URLs, thus triggering vulnerabilities when the program uses eval statements to parse templates.
History

Mon, 07 Apr 2025 15:30:00 +0000

Type Values Removed Values Added
First Time appeared Pbootcms
Pbootcms pbootcms
CPEs cpe:2.3:a:pbootcms:pbootcms:*:*:*:*:*:*:*:*
Vendors & Products Pbootcms
Pbootcms pbootcms

Fri, 21 Feb 2025 21:15:00 +0000

Type Values Removed Values Added
Weaknesses CWE-89
Metrics cvssV3_1

{'score': 5.1, 'vector': 'CVSS:3.1/AV:L/AC:L/PR:N/UI:N/S:U/C:L/I:L/A:N'}

ssvc

{'options': {'Automatable': 'no', 'Exploitation': 'poc', 'Technical Impact': 'total'}, 'version': '2.0.3'}


Fri, 21 Feb 2025 18:45:00 +0000

Type Values Removed Values Added
Description SQL Injection vulnerability in PbootCMS 1.4.1 in parsing if statements in templates, resulting in a malicious user's ability to contaminate template content by searching for page contamination URLs, thus triggering vulnerabilities when the program uses eval statements to parse templates.
References

cve-icon MITRE

Status: PUBLISHED

Assigner: mitre

Published:

Updated: 2025-02-21T21:08:09.646Z

Reserved: 2020-08-13T00:00:00.000Z

Link: CVE-2020-19248

cve-icon Vulnrichment

Updated: 2025-02-21T21:08:02.278Z

cve-icon NVD

Status : Analyzed

Published: 2025-02-21T19:15:10.093

Modified: 2025-04-07T15:05:33.257

Link: CVE-2020-19248

cve-icon Redhat

No data.