SQL Injection Vulnerability in PbootCMS by Pboot
CVE-2018-18211
8.1HIGH
What is CVE-2018-18211?
PbootCMS version 1.2.1 is susceptible to an SQL injection attack through HTTP POST data when accessing the api.php/cms/addform?fcode=1 endpoint. This vulnerability allows attackers to manipulate database queries, potentially leading to unauthorized access to sensitive information or disruption of service. It is crucial for users of affected versions to apply security patches and implement mitigation strategies to safeguard their applications.
