Description
A security vulnerability has been detected in PbootCMS up to 3.2.24. This vulnerability affects the function UserController::del/UserController::mod of the file apps/admin/controller/system/UserController.php of the component User Management. Such manipulation leads to cross-site request forgery. The attack may be performed from remote. The exploit has been disclosed publicly and may be used. Upgrading to version 3.2.25 is able to resolve this issue. The name of the patch is c25241a0964742cefb7f698efbb6c38b868d6ff7. It is advisable to upgrade the affected component.
Published: 2026-09-16
Score: 5.3 Medium
EPSS: < 1% Very Low
KEV: No
Impact: Cross-site request forgery
Action: Apply Patch
AI Analysis

Impact

The flaw exists in the UserController of PbootCMS’s admin system. During user deletion or modification, the application fails to validate a CSRF token and lacks proper authorization checks. The vulnerability allows an attacker to forge a request that causes the server to delete or modify user accounts without permission, potentially leading to unauthorized account changes, data loss, or exploitation of privileged accounts.

Affected Systems

The issue affects all releases of PbootCMS up to and including 3.2.24. Versions 3.2.25 and later contain the security fix that addresses the missing CSRF protection and authorization checks. Administrators should update to the patched release or apply the specific commit identified by c25241a0964742cefb7f698efbb6c38b868d6ff7.

Risk and Exploitability

The CVSS score of 5.3 reflects moderate severity, while the EPSS score of less than 1% indicates a very low likelihood of exploitation at present. The vulnerability is not listed in the CISA KEV catalog, and it is reported to be exploitable from a remote source, meaning an attacker can trigger the malicious request from outside the network. The lack of CSRF protection and insufficient privilege checks are the root weaknesses.

Generated by OpenCVE AI on September 18, 2026 at 05:38 UTC.

Remediation

No solution or workaround provided in the CVE record.

OpenCVE Recommended Actions

  • Upgrade PbootCMS to version 3.2.25 or later, applying the patch commit c25241a0964742cefb7f698efbb6c38b868d6ff7.
  • Implement CSRF token validation for all POST requests within the admin module, ensuring that the token is generated and checked for delete and modify user actions.
  • Add role‑based authorization checks so that only users with administrative rights can access the UserController::del and UserController::mod functions.
  • Continue to monitor log files for any unexpected user deletion or modification events to detect potential misuse.

Generated by OpenCVE AI on September 18, 2026 at 05:38 UTC.

Tracking

Sign in to view the affected projects.

Advisories

No advisories yet.

History

Wed, 16 Sep 2026 16:30:00 +0000

Type Values Removed Values Added
Metrics ssvc

{'options': {'Automatable': 'no', 'Exploitation': 'poc', 'Technical Impact': 'partial'}, 'version': '2.0.3'}


Wed, 16 Sep 2026 15:15:00 +0000

Type Values Removed Values Added
Description A security vulnerability has been detected in PbootCMS up to 3.2.24. This vulnerability affects the function UserController::del/UserController::mod of the file apps/admin/controller/system/UserController.php of the component User Management. Such manipulation leads to cross-site request forgery. The attack may be performed from remote. The exploit has been disclosed publicly and may be used. Upgrading to version 3.2.25 is able to resolve this issue. The name of the patch is c25241a0964742cefb7f698efbb6c38b868d6ff7. It is advisable to upgrade the affected component.
Title PbootCMS User Management UserController.php mod cross-site request forgery
First Time appeared Pbootcms
Pbootcms pbootcms
Weaknesses CWE-352
CWE-862
CPEs cpe:2.3:a:pbootcms:pbootcms:*:*:*:*:*:*:*:*
Vendors & Products Pbootcms
Pbootcms pbootcms
References
Metrics cvssV2_0

{'score': 5, 'vector': 'AV:N/AC:L/Au:N/C:N/I:P/A:N/E:POC/RL:OF/RC:C'}

cvssV3_0

{'score': 4.3, 'vector': 'CVSS:3.0/AV:N/AC:L/PR:N/UI:R/S:U/C:N/I:L/A:N/E:P/RL:O/RC:C'}

cvssV3_1

{'score': 4.3, 'vector': 'CVSS:3.1/AV:N/AC:L/PR:N/UI:R/S:U/C:N/I:L/A:N/E:P/RL:O/RC:C'}

cvssV4_0

{'score': 5.3, 'vector': 'CVSS:4.0/AV:N/AC:L/AT:N/PR:N/UI:P/VC:N/VI:L/VA:N/SC:N/SI:N/SA:N/E:P'}


Subscriptions

Pbootcms Pbootcms
cve-icon MITRE

Status: PUBLISHED

Assigner: VulDB

Published:

Updated: 2026-09-16T15:05:02.499Z

Reserved: 2026-09-16T08:01:43.835Z

Link: CVE-2026-92383

cve-icon Vulnrichment

Updated: 2026-09-16T15:04:59.189Z

cve-icon NVD

Status : Deferred

Published: 2026-09-16T15:19:01.673

Modified: 2026-09-16T17:53:40.500

Link: CVE-2026-92383

cve-icon Redhat

No data.

cve-icon OpenCVE Enrichment

Updated: 2026-09-19T22:37:50Z

Weaknesses
  • CWE-352

    Cross-Site Request Forgery (CSRF)

  • CWE-862

    Missing Authorization