SQL Injection Vulnerability in PbootCMS by PbootCMS
CVE-2026-79387
4.3MEDIUM
What is CVE-2026-79387?
An SQL injection vulnerability in PbootCMS versions 3.2.0 to 3.2.5 allows authenticated users to manipulate user account fields, including passwords and roles, through specially crafted parameters in the User/mod interface. This exploitation could lead to unauthorized changes and account takeover, posing a significant risk to user security.
