CVE-2021-28245: SQL Injection
Published Mar 31, 2021
·Updated
PbootCMS 3.0.4 contains a SQL injection vulnerability through index.php via the search parameter that can reveal sensitive information through adding an admin account.
Affected Software
1 affected component
Pbootcms Pbootcms=3.0.4
Event History
Mar 31, 2021
CVE Published
via MITRE·01:32 PM
Data Sourced
via MITRE·01:32 PM
Description
Frequently Asked Questions
1
What is the vulnerability ID?
The vulnerability ID is CVE-2021-28245.
2
What is the severity of CVE-2021-28245?
The severity of CVE-2021-28245 is high with a CVSS score of 7.5.
3
What is the affected software?
The affected software is PbootCMS version 3.0.4.
4
How can the SQL injection vulnerability in PbootCMS be exploited?
The SQL injection vulnerability can be exploited by manipulating the 'search' parameter in the 'index.php' file.
5
What can an attacker do with this vulnerability?
An attacker can exploit this vulnerability to reveal sensitive information by adding an admin account.