SQL injection vulnerability in PbootCMS versions 3.2.0 through 3.2.5 allows an authenticated user to modify arbitrary user account fields (including passwords and roles) via crafted parameters to the User/mod interface, enabling account takeover.
References
Configurations
No configuration.
History
No history.
Information
Published : 2026-09-09 21:17
Updated : 2026-09-14 15:17
NVD link : CVE-2026-79387
Mitre link : CVE-2026-79387
CVE.ORG link : CVE-2026-79387
JSON object : View
Products Affected
No product.
CWE
CWE-89
Improper Neutralization of Special Elements used in an SQL Command ('SQL Injection')
