A vulnerability was identified in PbootCMS up to 3.2.12. The impacted element is the function checkUsername of the file apps/home/controller/MemberController.php of the component Member Login. The manipulation of the argument Username leads to sql injection. The attack may be initiated remotely. The exploit is publicly available and might be used.
Metrics
Affected Vendors & Products
References
History
Fri, 20 Mar 2026 22:45:00 +0000
| Type | Values Removed | Values Added |
|---|---|---|
| Description | A vulnerability was identified in PbootCMS up to 3.2.12. The impacted element is the function checkUsername of the file apps/home/controller/MemberController.php of the component Member Login. The manipulation of the argument Username leads to sql injection. The attack may be initiated remotely. The exploit is publicly available and might be used. | |
| Title | PbootCMS Member Login MemberController.php checkUsername sql injection | |
| First Time appeared |
Pbootcms
Pbootcms pbootcms |
|
| Weaknesses | CWE-74 CWE-89 |
|
| CPEs | cpe:2.3:a:pbootcms:pbootcms:*:*:*:*:*:*:*:* | |
| Vendors & Products |
Pbootcms
Pbootcms pbootcms |
|
| References |
| |
| Metrics |
cvssV2_0
|
Status: PUBLISHED
Assigner: VulDB
Published: 2026-03-20T22:32:10.375Z
Updated: 2026-03-20T22:32:10.375Z
Reserved: 2026-03-20T14:25:45.837Z
Link: CVE-2026-4508
No data.
Status : Received
Published: 2026-03-20T23:16:48.493
Modified: 2026-03-20T23:16:48.493
Link: CVE-2026-4508
No data.