First published: Tue May 22 2018(Updated: )
An issue was discovered in PbootCMS v1.0.9. There is a SQL Injection that can get important information from the database via the \apps\home\controller\ParserController.php scode parameter.
Credit: cve@mitre.org
Affected Software | Affected Version | How to fix |
---|---|---|
Pbootcms Pbootcms | =1.0.9 |
Sign up to SecAlerts for real-time vulnerability data matched to your software, aggregated from hundreds of sources.
CVE-2018-11369 is a SQL Injection vulnerability in PbootCMS v1.0.9.
CVE-2018-11369 is classified as critical with a severity score of 9.8.
The vulnerability can be exploited by manipulating the 'scode' parameter in the ParserController.php file.
PbootCMS version 1.0.9 is affected by CVE-2018-11369.
It is recommended to update PbootCMS to a version that does not contain the SQL Injection vulnerability.