CVE-2025-46109

SQL Injection vulnerability in pbootCMS v.3.2.5 and v.3.2.10 allows a remote attacker to obtain sensitive information via a crafted GET request
References
Link Resource
http://cocr.cc/2025/04/17/pbootcms/ Exploit Third Party Advisory
https://github.com/pbootcmspro/PbootCMS/issues/22 Issue Tracking Third Party Advisory
Configurations

Configuration 1 (hide)

cpe:2.3:a:pbootcms:pbootcms:*:*:*:*:*:*:*:*

History

26 Jun 2025, 15:51

Type Values Removed Values Added
References () http://cocr.cc/2025/04/17/pbootcms/ - () http://cocr.cc/2025/04/17/pbootcms/ - Exploit, Third Party Advisory
References () https://github.com/pbootcmspro/PbootCMS/issues/22 - () https://github.com/pbootcmspro/PbootCMS/issues/22 - Issue Tracking, Third Party Advisory
First Time Pbootcms pbootcms
Pbootcms
CPE cpe:2.3:a:pbootcms:pbootcms:*:*:*:*:*:*:*:*

23 Jun 2025, 20:16

Type Values Removed Values Added
Summary
  • (es) La vulnerabilidad de inyección SQL en pbootCMS v.3.2.5 y v.3.2.10 permite que un atacante remoto obtenga información confidencial mediante una solicitud GET manipulada.

18 Jun 2025, 16:15

Type Values Removed Values Added
CWE CWE-89
CVSS v2 : unknown
v3 : unknown
v2 : unknown
v3 : 8.8

18 Jun 2025, 15:15

Type Values Removed Values Added
New CVE

Information

Published : 2025-06-18 15:15

Updated : 2025-06-26 15:51


NVD link : CVE-2025-46109

Mitre link : CVE-2025-46109

CVE.ORG link : CVE-2025-46109


JSON object : View

Products Affected

pbootcms

  • pbootcms
CWE
CWE-89

Improper Neutralization of Special Elements used in an SQL Command ('SQL Injection')