A weakness has been identified in PbootCMS up to 3.2.12. Impacted is an unknown function of the file /data/pbootcms.db of the component SQLite Database. Executing manipulation can lead to files or directories accessible. It is possible to launch the attack remotely. Attacks of this nature are highly complex. The exploitability is considered difficult. The exploit has been made available to the public and could be exploited. Modifying the configuration settings is advised.
History

Tue, 30 Dec 2025 19:15:00 +0000

Type Values Removed Values Added
CPEs cpe:2.3:a:pbootcms:pbootcms:*:*:*:*:*:*:*:*

Mon, 29 Dec 2025 23:15:00 +0000

Type Values Removed Values Added
First Time appeared Pbootcms
Pbootcms pbootcms
Vendors & Products Pbootcms
Pbootcms pbootcms

Mon, 29 Dec 2025 15:15:00 +0000

Type Values Removed Values Added
Metrics ssvc

{'options': {'Automatable': 'no', 'Exploitation': 'poc', 'Technical Impact': 'partial'}, 'version': '2.0.3'}


Sun, 28 Dec 2025 20:45:00 +0000

Type Values Removed Values Added
Description A weakness has been identified in PbootCMS up to 3.2.12. Impacted is an unknown function of the file /data/pbootcms.db of the component SQLite Database. Executing manipulation can lead to files or directories accessible. It is possible to launch the attack remotely. Attacks of this nature are highly complex. The exploitability is considered difficult. The exploit has been made available to the public and could be exploited. Modifying the configuration settings is advised.
Title PbootCMS SQLite Database pbootcms.db file access
Weaknesses CWE-425
CWE-552
References
Metrics cvssV2_0

{'score': 2.6, 'vector': 'AV:N/AC:H/Au:N/C:P/I:N/A:N/E:POC/RL:W/RC:UR'}

cvssV3_0

{'score': 3.7, 'vector': 'CVSS:3.0/AV:N/AC:H/PR:N/UI:N/S:U/C:L/I:N/A:N/E:P/RL:W/RC:R'}

cvssV3_1

{'score': 3.7, 'vector': 'CVSS:3.1/AV:N/AC:H/PR:N/UI:N/S:U/C:L/I:N/A:N/E:P/RL:W/RC:R'}

cvssV4_0

{'score': 6.3, 'vector': 'CVSS:4.0/AV:N/AC:H/AT:N/PR:N/UI:N/VC:L/VI:N/VA:N/SC:N/SI:N/SA:N/E:P'}


cve-icon MITRE

Status: PUBLISHED

Assigner: VulDB

Published: 2025-12-28T20:32:07.587Z

Updated: 2025-12-29T14:55:49.904Z

Reserved: 2025-12-27T16:47:06.711Z

Link: CVE-2025-15153

cve-icon Vulnrichment

Updated: 2025-12-29T14:55:47.285Z

cve-icon NVD

Status : Analyzed

Published: 2025-12-28T21:15:54.107

Modified: 2025-12-30T19:01:36.847

Link: CVE-2025-15153

cve-icon Redhat

No data.