Vulnerability Description
SQL Injection vulnerability in PbootCMS 1.4.1 in parsing if statements in templates, resulting in a malicious user's ability to contaminate template content by searching for page contamination URLs, thus triggering vulnerabilities when the program uses eval statements to parse templates.
CVSS Score
MEDIUM
Affected Products
| Vendor | Product | Versions |
|---|---|---|
| Pbootcms | Pbootcms | <= 1.4.1 |
Related Weaknesses (CWE)
References
- https://github.com/SticKManII/SticKManII.github.io/tree/master/2019/07/31/PbootCThird Party Advisory
- https://unh3x.github.io/2019/07/19/PbootCMSv1.4.1_Template_Injection/ExploitThird Party Advisory
FAQ
What is CVE-2020-19248?
CVE-2020-19248 is a vulnerability with a CVSS score of 5.1 (MEDIUM). SQL Injection vulnerability in PbootCMS 1.4.1 in parsing if statements in templates, resulting in a malicious user's ability to contaminate template content by searching for page contamination URLs, t...
How severe is CVE-2020-19248?
CVE-2020-19248 has been rated MEDIUM with a CVSS base score of 5.1/10. Review the CVSS metrics above for detailed severity breakdown.
Is there a patch for CVE-2020-19248?
Check the references section above for vendor advisories and patch information. Affected products include: Pbootcms Pbootcms.