SQL Injection Vulnerability in PbootCMS Admin Controller
CVE-2018-18450
9.8CRITICAL
What is CVE-2018-18450?
The PbootCMS application contains a SQL injection vulnerability in the SingleController.php file. This issue arises when improperly sanitized user input is passed to the database via POST requests to the admin.php endpoint. Successful exploitation may allow an attacker to manipulate database queries, potentially leading to unauthorized data access or modification. It is crucial to update to version 1.3.0 build 2018-11-12 or later to mitigate this security risk.
