Vulnerability Description
PbootCMS v0.9.8 has CSRF via an admin.php/Message/mod/id/19.html?backurl=/index.php request, resulting in PHP code injection in the recontent parameter.
CVSS Score
HIGH
Affected Products
| Vendor | Product | Versions |
|---|---|---|
| Pbootcms | Pbootcms | 0.9.8 |
Related Weaknesses (CWE)
References
- https://github.com/vQAQv/Request-CVE-ID-PoC/blob/master/PbootCMS/v0.9.8/CSRF.mdExploitThird Party Advisory
- https://github.com/vQAQv/Request-CVE-ID-PoC/blob/master/PbootCMS/v0.9.8/CSRF.mdExploitThird Party Advisory
FAQ
What is CVE-2018-10132?
CVE-2018-10132 is a vulnerability with a CVSS score of 8.8 (HIGH). PbootCMS v0.9.8 has CSRF via an admin.php/Message/mod/id/19.html?backurl=/index.php request, resulting in PHP code injection in the recontent parameter.
How severe is CVE-2018-10132?
CVE-2018-10132 has been rated HIGH with a CVSS base score of 8.8/10. Review the CVSS metrics above for detailed severity breakdown.
Is there a patch for CVE-2018-10132?
Check the references section above for vendor advisories and patch information. Affected products include: Pbootcms Pbootcms.