Description
A security vulnerability has been detected in PbootCMS up to 3.2.12. The affected element is the function get_user_ip of the file core/function/handle.php of the component Header Handler. The manipulation of the argument X-Forwarded-For leads to use of less trusted source. The attack can be initiated remotely. The exploit has been disclosed publicly and may be used.
Problem types
Timeline
| 2025-12-27: | Advisory disclosed |
| 2025-12-27: | VulDB entry created |
| 2025-12-27: | VulDB entry last update |
Credits
pemic (VulDB User)
References
vuldb.com/?id.338532 (VDB-338532 | PbootCMS Header handle.php get_user_ip less trusted source)
vuldb.com/?ctiid.338532 (VDB-338532 | CTI Indicators (IOB, IOC, IOA))
vuldb.com/?submit.719818 (Submit #719818 | PbootCMS 3.2.12 get_user_ip IP Address Spoofing)
note-hxlab.wetolink.com/share/JyBNgF8JagWQ
Data based on CVE®. Copyright © 1999-2025, The MITRE Corporation. All rights reserved.