Impact
The flaw exists in the UserController of PbootCMS’s admin system. During user deletion or modification, the application fails to validate a CSRF token and lacks proper authorization checks. The vulnerability allows an attacker to forge a request that causes the server to delete or modify user accounts without permission, potentially leading to unauthorized account changes, data loss, or exploitation of privileged accounts.
Affected Systems
The issue affects all releases of PbootCMS up to and including 3.2.24. Versions 3.2.25 and later contain the security fix that addresses the missing CSRF protection and authorization checks. Administrators should update to the patched release or apply the specific commit identified by c25241a0964742cefb7f698efbb6c38b868d6ff7.
Risk and Exploitability
The CVSS score of 5.3 reflects moderate severity, while the EPSS score of less than 1% indicates a very low likelihood of exploitation at present. The vulnerability is not listed in the CISA KEV catalog, and it is reported to be exploitable from a remote source, meaning an attacker can trigger the malicious request from outside the network. The lack of CSRF protection and insufficient privilege checks are the root weaknesses.
OpenCVE Enrichment