PT-2024-17739 · Pbootcms · Pbootcms

·

CVE-2024-12789

·

Published

2024-12-19

·

Updated

2025-01-10

CVSS v3.1

9.8

Critical

VectorAV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H
Name of the Vulnerable Software and Affected Versions PbootCMS versions up to 3.2.3
Description A critical issue has been found in PbootCMS, affecting an unknown part of the file apps/home/controller/IndexController.php. The manipulation of the argument tag leads to code injection. It is possible to initiate the attack remotely. The exploit has been disclosed to the public and may be used.
Recommendations For PbootCMS versions up to 3.2.3, upgrade to version 3.2.4 to address this issue. As a temporary workaround, consider restricting access to the affected component, specifically the IndexController.php file, until the update is applied.

Exploit

Fix

Special Elements Injection

Code Injection

Found an issue in the description? Have something to add? Feel free to write us 👾

Weakness Enumeration

Related Identifiers

CVE-2024-12789

Affected Products

Pbootcms