Cross-Site Request Forgery in PbootCMS User Management by PbootCMS
CVE-2026-92383
Key Information:
Badges
What is CVE-2026-92383?
A security vulnerability has been identified in PbootCMS affecting versions up to 3.2.24, specifically within the UserController module. The vulnerability originates from inadequate validation within functions responsible for user deletion and modification, exposing the application to cross-site request forgery exploits. This flaw allows attackers to potentially execute unauthorized requests from remote locations, compromising user data integrity and security. To mitigate this risk, users are recommended to upgrade to PbootCMS version 3.2.25, which addresses this issue through a critical patch. The patch identifier is c25241a0964742cefb7f698efbb6c38b868d6ff7.
Affected Version(s)
PbootCMS 3.2.0
PbootCMS 3.2.1
PbootCMS 3.2.2
Exploit Proof of Concept (PoC)
PoC code is written by security researchers to demonstrate the vulnerability can be exploited. PoC code is also a key component for weaponization which could lead to ransomware.
References
CVSS V4
Timeline
- ๐ก
Public PoC available
- ๐พ
Exploit known to exist
Vulnerability published
Vulnerability Reserved
