Impact
The vulnerability resides in the decode_string function of the ContentController.php file within PbootCMS's Template Rendering component. By manipulating the Title argument, an attacker can inject malicious scripts that are rendered in the browser, leading to cross‑site scripting. The flaw allows remote exploitation, as the attacker can supply the malicious Title via a remote request, and an exploit is publicly available.
Affected Systems
The flaw affects PbootCMS versions up to and including 3.2.22. Any installation that relies on the Template Rendering component and accepts user‑supplied Title values without proper sanitization is at risk.
Risk and Exploitability
With a CVSS score of 5.1, the vulnerability is considered medium severity. The EPSS score of less than 1% indicates a low probability of widespread exploitation at present, and the issue is not listed in the CISA KEV catalog. Nevertheless, because the flaw is remotely exploitable and an exploit is public, administrators should be aware that attackers can inject arbitrary scripting payloads when the Title field is manipulated.
OpenCVE Enrichment