← Zuruck zu CVEs
CVE-2020-19248
MEDIUM5.1
Beschreibung
SQL Injection vulnerability in PbootCMS 1.4.1 in parsing if statements in templates, resulting in a malicious user's ability to contaminate template content by searching for page contamination URLs, thus triggering vulnerabilities when the program uses eval statements to parse templates.
CVE Details
CVSS v3.1 Bewertung5.1
SchweregradMEDIUM
CVSS VektorCVSS:3.1/AV:L/AC:L/PR:N/UI:N/S:U/C:L/I:L/A:N
AngriffsvektorLOCAL
KomplexitatLOW
Erforderliche PrivilegienNONE
BenutzerinteraktionNONE
Veroffentlicht2/21/2025
Zuletzt geandert4/7/2025
Quellenvd
Honeypot-Sichtungen0
Betroffene Produkte
pbootcms:pbootcms
Schwachen (CWE)
CWE-89
Referenzen
IOC Korrelationen
Keine Korrelationen erfasst
This product uses data from the NVD API but is not endorsed or certified by the NVD.