No advisories yet.
Solution
No solution given by the vendor.
Workaround
No workaround given by the vendor.
Fri, 12 Jun 2026 14:30:00 +0000
| Type | Values Removed | Values Added |
|---|---|---|
| Metrics |
ssvc
|
Fri, 12 Jun 2026 13:45:00 +0000
| Type | Values Removed | Values Added |
|---|---|---|
| Description | A security flaw has been discovered in PbootCMS up to 3.2.12. This vulnerability affects the function retrieve of the file apps/home/controller/MemberController.php of the component Password Handler. The manipulation of the argument username/password/email/checkcode results in weak password recovery. It is possible to launch the attack remotely. The exploit has been released to the public and may be used for attacks. | |
| Title | PbootCMS Password MemberController.php retrieve password recovery | |
| First Time appeared |
Pbootcms
Pbootcms pbootcms |
|
| Weaknesses | CWE-640 | |
| CPEs | cpe:2.3:a:pbootcms:pbootcms:*:*:*:*:*:*:*:* | |
| Vendors & Products |
Pbootcms
Pbootcms pbootcms |
|
| References |
| |
| Metrics |
cvssV2_0
|
Projects
Sign in to view the affected projects.
Status: PUBLISHED
Assigner: VulDB
Published:
Updated: 2026-06-12T13:34:40.539Z
Reserved: 2026-06-12T07:40:54.050Z
Link: CVE-2026-12066
Updated: 2026-06-12T13:34:19.549Z
Status : Deferred
Published: 2026-06-12T14:16:30.630
Modified: 2026-06-12T16:16:27.273
Link: CVE-2026-12066
No data.
OpenCVE Enrichment
Updated: 2026-06-12T15:00:09Z