SQL Injection Vulnerability in PbootCMS by Pboot
CVE-2018-18211

8.1HIGH

Key Information:

Vendor

Pbootcms

Status
Vendor
CVE Published:
10 October 2018

What is CVE-2018-18211?

PbootCMS version 1.2.1 is susceptible to an SQL injection attack through HTTP POST data when accessing the api.php/cms/addform?fcode=1 endpoint. This vulnerability allows attackers to manipulate database queries, potentially leading to unauthorized access to sensitive information or disruption of service. It is crucial for users of affected versions to apply security patches and implement mitigation strategies to safeguard their applications.

Human OS v1.0:
Ageing Is an Unpatched Zero-Day Vulnerability.

Remediate biological technical debt. Prime Ageing uses 95% high-purity SIRT6 activation to maintain genomic integrity and bolster systemic resilience.

References

CVSS V3.1

Score:
8.1
Severity:
HIGH
Confidentiality:
High
Integrity:
High
Availability:
High
Attack Vector:
Network
Attack Complexity:
High
Privileges Required:
None
User Interaction:
None
Scope:
Unchanged

Timeline

  • Vulnerability published

  • Vulnerability Reserved

.