A security vulnerability has been detected in PbootCMS up...
Moderate severity
Unreviewed
Published
Dec 28, 2025
to the GitHub Advisory Database
•
Updated Dec 30, 2025
Description
Published by the National Vulnerability Database
Dec 28, 2025
Published to the GitHub Advisory Database
Dec 28, 2025
Last updated
Dec 30, 2025
A security vulnerability has been detected in PbootCMS up to 3.2.12. The affected element is the function get_user_ip of the file core/function/handle.php of the component Header Handler. The manipulation of the argument X-Forwarded-For leads to use of less trusted source. The attack can be initiated remotely. The exploit has been disclosed publicly and may be used.
References