First published: Wed Mar 31 2021(Updated: )
PbootCMS 3.0.4 contains a SQL injection vulnerability through index.php via the search parameter that can reveal sensitive information through adding an admin account.
Credit: cve@mitre.org
Affected Software | Affected Version | How to fix |
---|---|---|
Pbootcms Pbootcms | =3.0.4 |
Sign up to SecAlerts for real-time vulnerability data matched to your software, aggregated from hundreds of sources.
The vulnerability ID is CVE-2021-28245.
The severity of CVE-2021-28245 is high with a CVSS score of 7.5.
The affected software is PbootCMS version 3.0.4.
The SQL injection vulnerability can be exploited by manipulating the 'search' parameter in the 'index.php' file.
An attacker can exploit this vulnerability to reveal sensitive information by adding an admin account.