Remote Code Execution Vulnerability in PbootCMS by PbootCMS
CVE-2018-19595
9.8CRITICAL
What is CVE-2018-19595?
PbootCMS version 1.3.1 enables remote attackers to execute arbitrary PHP code through a crafted URL that exploits a flawed mechanism in the ParserController. The vulnerability arises from the improper handling of the 'eval' function when mixed case letters are used, which could lead to unauthorized commands being executed on the server. Proper validation and security measures must be implemented to mitigate this vulnerability.
