CVE-2024-12789

A vulnerability was found in PbootCMS up to 3.2.3. It has been classified as critical. This affects an unknown part of the file apps/home/controller/IndexController.php. The manipulation of the argument tag leads to code injection. It is possible to initiate the attack remotely. The exploit has been disclosed to the public and may be used. Upgrading to version 3.2.4 is able to address this issue. It is recommended to upgrade the affected component.
References
Link Resource
https://gist.github.com/J1rrY-learn/8e52bf055fd1806ada81ae1ff25dd817 Broken Link
https://vuldb.com/?ctiid.288969 Permissions Required VDB Entry
https://vuldb.com/?id.288969 Third Party Advisory VDB Entry
https://vuldb.com/?submit.465122 Third Party Advisory VDB Entry
Configurations

Configuration 1 (hide)

cpe:2.3:a:pbootcms:pbootcms:*:*:*:*:*:*:*:*

History

10 Jan 2025, 21:42

Type Values Removed Values Added
First Time Pbootcms pbootcms
Pbootcms
Summary
  • (es) Se ha encontrado una vulnerabilidad en PbootCMS hasta la versión 3.2.3. Se ha clasificado como crítica. Afecta a una parte desconocida del archivo apps/home/controller/IndexController.php. La manipulación de la etiqueta de argumento provoca la inyección de código. Es posible iniciar el ataque de forma remota. El exploit se ha hecho público y puede utilizarse. La actualización a la versión 3.2.4 puede solucionar este problema. Se recomienda actualizar el componente afectado.
CPE cpe:2.3:a:pbootcms:pbootcms:*:*:*:*:*:*:*:*
References () https://gist.github.com/J1rrY-learn/8e52bf055fd1806ada81ae1ff25dd817 - () https://gist.github.com/J1rrY-learn/8e52bf055fd1806ada81ae1ff25dd817 - Broken Link
References () https://vuldb.com/?ctiid.288969 - () https://vuldb.com/?ctiid.288969 - Permissions Required, VDB Entry
References () https://vuldb.com/?id.288969 - () https://vuldb.com/?id.288969 - Third Party Advisory, VDB Entry
References () https://vuldb.com/?submit.465122 - () https://vuldb.com/?submit.465122 - Third Party Advisory, VDB Entry

19 Dec 2024, 17:15

Type Values Removed Values Added
New CVE

Information

Published : 2024-12-19 17:15

Updated : 2025-01-10 21:42


NVD link : CVE-2024-12789

Mitre link : CVE-2024-12789

CVE.ORG link : CVE-2024-12789


JSON object : View

Products Affected

pbootcms

  • pbootcms
CWE
CWE-74

Improper Neutralization of Special Elements in Output Used by a Downstream Component ('Injection')

CWE-94

Improper Control of Generation of Code ('Code Injection')