CVE-2020-19248

SQL Injection vulnerability in PbootCMS 1.4.1 in parsing if statements in templates, resulting in a malicious user's ability to contaminate template content by searching for page contamination URLs, thus triggering vulnerabilities when the program uses eval statements to parse templates.
Configurations

Configuration 1 (hide)

cpe:2.3:a:pbootcms:pbootcms:*:*:*:*:*:*:*:*

History

07 Apr 2025, 15:05

Type Values Removed Values Added
First Time Pbootcms
Pbootcms pbootcms
CPE cpe:2.3:a:pbootcms:pbootcms:*:*:*:*:*:*:*:*
Summary
  • (es) Vulnerabilidad de inyección SQL en PbootCMS 1.4.1 al analizar declaraciones if en plantillas, lo que da como resultado la capacidad de un usuario malintencionado de contaminar el contenido de la plantilla mediante la búsqueda de URL de contaminación de páginas, lo que desencadena vulnerabilidades cuando el programa usa declaraciones eval para analizar plantillas.
References () https://github.com/SticKManII/SticKManII.github.io/tree/master/2019/07/31/PbootCMSv1-4-1-%E5%89%8D%E5%8F%B0%E6%90%9C%E7%B4%A2%E9%A1%B5%E9%9D%A2%E6%A8%A1%E6%9D%BF%E6%B3%A8%E5%85%A5 - () https://github.com/SticKManII/SticKManII.github.io/tree/master/2019/07/31/PbootCMSv1-4-1-%E5%89%8D%E5%8F%B0%E6%90%9C%E7%B4%A2%E9%A1%B5%E9%9D%A2%E6%A8%A1%E6%9D%BF%E6%B3%A8%E5%85%A5 - Third Party Advisory
References () https://unh3x.github.io/2019/07/19/PbootCMSv1.4.1_Template_Injection/ - () https://unh3x.github.io/2019/07/19/PbootCMSv1.4.1_Template_Injection/ - Exploit, Third Party Advisory

21 Feb 2025, 21:15

Type Values Removed Values Added
CVSS v2 : unknown
v3 : unknown
v2 : unknown
v3 : 5.1
CWE CWE-89

21 Feb 2025, 19:15

Type Values Removed Values Added
New CVE

Information

Published : 2025-02-21 19:15

Updated : 2025-04-07 15:05


NVD link : CVE-2020-19248

Mitre link : CVE-2020-19248

CVE.ORG link : CVE-2020-19248


JSON object : View

Products Affected

pbootcms

  • pbootcms
CWE
CWE-89

Improper Neutralization of Special Elements used in an SQL Command ('SQL Injection')