CVE-2020-19248
CVSS 3.1 Score 5.1 of 10 (medium)
Details
Published Feb 21, 2025
CWE ID 89
Summary
CVE-2020-19248 is a SQL Injection vulnerability affecting PbootCMS 1.4.1. Malicious users can exploit this issue by contaminating template content with malicious URLs during the parsing of if statements. If the program uses eval statements to parse templates, these URLs can trigger vulnerabilities, potentially leading to unintended database queries and data leakage. This vulnerability poses a significant risk to websites utilizing PbootCMS and encourages immediate patching to mitigate the threat.
Prevent cyber attacks with Recorded Future by prioritizing and patching critical vulnerabilities being exploited by threat actors targeting your industry. Book your demo to learn more.
Share