PHP Code Injection in PbootCMS Version 0.9.8
CVE-2018-10133
9.8CRITICAL
What is CVE-2018-10133?
PbootCMS version 0.9.8 is susceptible to PHP code injection due to improper handling of the IF label in certain files. Specifically, the vulnerability can be exploited via index.php/About/6.html or admin.php/Site/index.html, where the parserIfLabel function in apps/home/controller/ParserController.php is compromised, allowing malicious input to be executed. This flaw poses serious risks for web applications using this version of PbootCMS, highlighting the necessity for immediate updates and patching to secure user data and application integrity.
