Cross-Site Scripting Flaw in PbootCMS by PbootCMS
CVE-2020-18456
4.8MEDIUM
What is CVE-2020-18456?
A Cross-Site Scripting (XSS) vulnerability in PbootCMS version 1.3.7 allows attackers to inject malicious scripts via the title parameter in the mod function within SingleController.php. This can lead to unauthorized actions being executed in the context of a user's session, potentially compromising user data and session integrity.
