CVE-2026-4509: PbootCMS File Upload file.php incomplete blacklist
A security flaw has been discovered in PbootCMS up to 3.2.12. This affects an unknown function of the file core/function/file.php of the component File Upload. The manipulation of the argument black results in incomplete blacklist. The attack may be launched remotely. The exploit has been released to the public and may be used for attacks.
Affected Software
Event History
Frequently Asked Questions
What is the severity of CVE-2026-4509?
The severity of CVE-2026-4509 has not been officially rated, but it poses a significant risk due to incomplete input validation.
How do I fix CVE-2026-4509?
To fix CVE-2026-4509, update PbootCMS to version 3.2.13 or later, which addresses this vulnerability.
What impact does CVE-2026-4509 have on PbootCMS?
CVE-2026-4509 allows for potential unauthorized file uploads and may lead to remote code execution if exploited.
Which versions of PbootCMS are affected by CVE-2026-4509?
CVE-2026-4509 affects PbootCMS versions up to and including 3.2.12.
What kind of attack is possible due to CVE-2026-4509?
An attacker may exploit CVE-2026-4509 to upload malicious files via the incomplete blacklist in file.php.