Description
A security flaw has been discovered in PbootCMS up to 3.2.12. This vulnerability affects the function retrieve of the file apps/home/controller/MemberController.php of the component Password Handler. The manipulation of the argument username/password/email/checkcode results in weak password recovery. It is possible to launch the attack remotely. The exploit has been released to the public and may be used for attacks.
Published: 2026-06-12
Score: 6.9 Medium
EPSS: n/a
KEV: No
Impact: n/a
Action: n/a
AI Analysis

Impact

A flaw in the password recovery function of PbootCMS allows remote manipulation of the username, password, email and checkcode parameters, resulting in weak verification and enabling an attacker to reset credentials without proper authorization. This leads to unauthorized access to user accounts, effectively allowing an account takeover. The weakness is identified as CWE-640, reflecting a weak password recovery procedure.

Affected Systems

The vulnerability impacts PbootCMS version 3.2.12 and earlier. Affected users are those deploying these or earlier releases of the CMS.

Risk and Exploitability

The CVSS score of 6.9 indicates moderate severity. The EPSS score is not provided, but the vulnerability is publicly exploitable and can be triggered remotely, allowing attackers to recover passwords and take over accounts. Since it is not listed in the CISA KEV catalog, there is currently no alert indicating active exploitation, yet the public availability of an exploit increases the likelihood of future attacks.

Generated by OpenCVE AI on June 12, 2026 at 14:52 UTC.

Remediation

No vendor fix or workaround currently provided.

OpenCVE Recommended Actions

  • Apply the vendor’s security patch that rectifies the weak recovery logic, or upgrade PbootCMS to a version newer than 3.2.12 once available.
  • Until a patch is applied, restrict access to the password recovery endpoint or add additional verification such as time‑bound one‑time codes or multi‑factor authentication.
  • Monitor account activity for abnormal password reset attempts and enforce strong password policies to limit potential damage if a reset is compromised.

Generated by OpenCVE AI on June 12, 2026 at 14:52 UTC.

Tracking

Sign in to view the affected projects.

Advisories

No advisories yet.

History

Fri, 12 Jun 2026 14:30:00 +0000

Type Values Removed Values Added
Metrics ssvc

{'options': {'Automatable': 'yes', 'Exploitation': 'poc', 'Technical Impact': 'partial'}, 'version': '2.0.3'}


Fri, 12 Jun 2026 13:45:00 +0000

Type Values Removed Values Added
Description A security flaw has been discovered in PbootCMS up to 3.2.12. This vulnerability affects the function retrieve of the file apps/home/controller/MemberController.php of the component Password Handler. The manipulation of the argument username/password/email/checkcode results in weak password recovery. It is possible to launch the attack remotely. The exploit has been released to the public and may be used for attacks.
Title PbootCMS Password MemberController.php retrieve password recovery
First Time appeared Pbootcms
Pbootcms pbootcms
Weaknesses CWE-640
CPEs cpe:2.3:a:pbootcms:pbootcms:*:*:*:*:*:*:*:*
Vendors & Products Pbootcms
Pbootcms pbootcms
References
Metrics cvssV2_0

{'score': 7.5, 'vector': 'AV:N/AC:L/Au:N/C:P/I:P/A:P/E:POC/RL:ND/RC:UR'}

cvssV3_0

{'score': 7.3, 'vector': 'CVSS:3.0/AV:N/AC:L/PR:N/UI:N/S:U/C:L/I:L/A:L/E:P/RL:X/RC:R'}

cvssV3_1

{'score': 7.3, 'vector': 'CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:L/I:L/A:L/E:P/RL:X/RC:R'}

cvssV4_0

{'score': 6.9, 'vector': 'CVSS:4.0/AV:N/AC:L/AT:N/PR:N/UI:N/VC:L/VI:L/VA:L/SC:N/SI:N/SA:N/E:P'}


Subscriptions

Pbootcms Pbootcms
cve-icon MITRE

Status: PUBLISHED

Assigner: VulDB

Published:

Updated: 2026-06-12T13:34:40.539Z

Reserved: 2026-06-12T07:40:54.050Z

Link: CVE-2026-12066

cve-icon Vulnrichment

Updated: 2026-06-12T13:34:19.549Z

cve-icon NVD

Status : Deferred

Published: 2026-06-12T14:16:30.630

Modified: 2026-06-12T16:16:27.273

Link: CVE-2026-12066

cve-icon Redhat

No data.

cve-icon OpenCVE Enrichment

Updated: 2026-06-12T20:00:17Z

Weaknesses
  • CWE-640

    Weak Password Recovery Mechanism for Forgotten Password