CVE-2026-79387: SQL Injection
Published Sep 9, 2026
·Updated
SQL injection vulnerability in PbootCMS versions 3.2.0 through 3.2.5 allows an authenticated user to modify arbitrary user account fields (including passwords and roles) via crafted parameters to the User/mod interface, enabling account takeover.
Affected Software
1 affected component
Pbootcms Pbootcms>=3.2.0<=3.2.5
Event History
Sep 9, 2026
CVE Published
via NVD·09:17 PM
Data Sourced
via NVD·09:17 PM
Description