A security flaw has been discovered in PbootCMS up to 3.2.12. This affects an unknown function of the file core/function/file.php of the component File Upload. The manipulation of the argument black results in incomplete blacklist. The attack may be launched remotely. The exploit has been released to the public and may be used for attacks.
Metrics
Affected Vendors & Products
References
History
Sat, 21 Mar 2026 06:15:00 +0000
| Type | Values Removed | Values Added |
|---|---|---|
| Description | A security flaw has been discovered in PbootCMS up to 3.2.12. This affects an unknown function of the file core/function/file.php of the component File Upload. The manipulation of the argument black results in incomplete blacklist. The attack may be launched remotely. The exploit has been released to the public and may be used for attacks. | |
| Title | PbootCMS File Upload file.php incomplete blacklist | |
| First Time appeared |
Pbootcms
Pbootcms pbootcms |
|
| Weaknesses | CWE-183 CWE-184 |
|
| CPEs | cpe:2.3:a:pbootcms:pbootcms:*:*:*:*:*:*:*:* | |
| Vendors & Products |
Pbootcms
Pbootcms pbootcms |
|
| References |
| |
| Metrics |
cvssV2_0
|
Status: PUBLISHED
Assigner: VulDB
Published:
Updated: 2026-03-21T06:02:10.118Z
Reserved: 2026-03-20T14:25:50.786Z
Link: CVE-2026-4509
No data.
Status : Received
Published: 2026-03-21T06:16:14.160
Modified: 2026-03-21T06:16:14.160
Link: CVE-2026-4509
No data.
OpenCVE Enrichment
No data.