SQL Injection Vulnerability in PbootCMS by Escape Wang
CVE-2018-16357
9.8CRITICAL
What is CVE-2018-16357?
A SQL injection vulnerability exists in PbootCMS, particularly through the 'order' parameter in the api.php/Cms/search endpoint. This flaw allows an attacker to manipulate SQL queries, which can lead to unauthorized access to sensitive database information or even complete database compromise. Proper sanitization and validation of user input are crucial to prevent such attacks.
