CVE-2018-11369: SQL Injection
Published May 22, 2018
·Updated
An issue was discovered in PbootCMS v1.0.9. There is a SQL Injection that can get important information from the database via the \apps\home\controller\ParserController.php scode parameter.
Affected Software
1 affected component
Pbootcms Pbootcms=1.0.9
Event History
May 22, 2018
CVE Published
via MITRE·03:00 PM
Data Sourced
via MITRE·03:00 PM
Description
Frequently Asked Questions
1
What is CVE-2018-11369?
CVE-2018-11369 is a SQL Injection vulnerability in PbootCMS v1.0.9.
2
How severe is CVE-2018-11369?
CVE-2018-11369 is classified as critical with a severity score of 9.8.
3
How can the SQL Injection vulnerability in PbootCMS v1.0.9 be exploited?
The vulnerability can be exploited by manipulating the 'scode' parameter in the ParserController.php file.
4
What is affected by CVE-2018-11369?
PbootCMS version 1.0.9 is affected by CVE-2018-11369.
5
Is there a fix available for CVE-2018-11369?
It is recommended to update PbootCMS to a version that does not contain the SQL Injection vulnerability.