CVE-2020-19248

CVSS 3.1 Score 5.1 of 10 (medium)

Details

Published Feb 21, 2025
CWE ID 89

Summary

CVE-2020-19248 is a SQL Injection vulnerability affecting PbootCMS 1.4.1. Malicious users can exploit this issue by contaminating template content with malicious URLs during the parsing of if statements. If the program uses eval statements to parse templates, these URLs can trigger vulnerabilities, potentially leading to unintended database queries and data leakage. This vulnerability poses a significant risk to websites utilizing PbootCMS and encourages immediate patching to mitigate the threat.

Ligh bulbPrevent cyber attacks with Recorded Future by prioritizing and patching critical vulnerabilities being exploited by threat actors targeting your industry. Book your demo to learn more.

Share