PT-2026-93818 · Git · Pbootcms

·

CVE-2026-92383

·

Published

2026-09-16

·

Updated

2026-09-16

CVSS v2.0

5.0

Medium

VectorAV:N/AC:L/Au:N/C:N/I:P/A:N
Name of the Vulnerable Software and Affected Versions PbootCMS versions prior to 3.2.25
Description A cross-site request forgery issue exists in the User Management component. A remote attacker can manipulate the UserController::del() and UserController::mod() functions within the apps/admin/controller/system/UserController.php file.
Recommendations Upgrade to version 3.2.25.

Exploit

Fix

Missing Authorization

CSRF

Found an issue in the description? Have something to add? Feel free to write us 👾

Weakness Enumeration

Related Identifiers

CVE-2026-92383

Affected Products

Pbootcms