PbootCMS是PbootCMS开源的一款使用PHP语言开发的开源企业建站内容管理系统(CMS)。 PbootCMS 3.2.12及之前版本存在访问控制错误漏洞,该漏洞源于Backend组件文件apps/admin/controller/system/UserController.php中未知功能对参数Field的错误操作,可能导致访问控制不当。
Although we use advanced large model technology, its output may still contain inaccurate or outdated information.Shenlong tries to ensure data accuracy, but please verify and judge based on the actual situation.
| Vendor | Product | Affected Versions | CPE | Subscribe |
|---|---|---|---|---|
| - | PbootCMS | 3.2.0 |
cpe:2.3:a:pbootcms:pbootcms:*:*:*:*:*:*:*:*
|
|
| # | POC Description | Source Link | Shenlong Link |
|---|
No public POC found.
Login to generate AI POC| CVE-2026-4509 | 6.3 MEDIUM | PbootCMS File Upload file.php incomplete blacklist |
| CVE-2026-4510 | 4.3 MEDIUM | PbootCMS Parameter MemberController.php alert_location cross site scripting |
No comments yet