Cross-Site Scripting Vulnerability in PbootCMS Admin Interface
CVE-2025-29389
6.1MEDIUM
What is CVE-2025-29389?
PbootCMS version 3.2.9 includes a Cross-Site Scripting (XSS) vulnerability found in the admin.php interface. This security flaw allows an attacker to inject malicious scripts through crafted URL parameters. If exploited, this could lead to unauthorized actions executed in the context of an authenticated user session, potentially compromising sensitive information or manipulating website content. It is critical to apply necessary security patches and validate user inputs to mitigate such risks.
