CVE-2025-15153
Unknown
Unknown - Not Provided
Unauthorized File Access via SQLite Database in PbootCMS
Publication date: 2025-12-28
Last updated on: 2026-04-29
Assigner: VulDB
Description
Description
A weakness has been identified in PbootCMS up to 3.2.12. Impacted is an unknown function of the file /data/pbootcms.db of the component SQLite Database. Executing a manipulation can lead to files or directories accessible. It is possible to launch the attack remotely. Attacks of this nature are highly complex. The exploitability is considered difficult. The exploit has been made available to the public and could be used for attacks. Modifying the configuration settings is advised.
CVSS Scores
EPSS Scores
| Probability: | |
| Percentile: |
Meta Information
Affected Vendors & Products
| Vendor | Product | Version / Range |
|---|---|---|
| pbootcms | pbootcms | 3.2.12 |
Helpful Resources
Exploitability
| CWE ID | Description |
|---|---|
| CWE-425 | The web application does not adequately enforce appropriate authorization on all restricted URLs, scripts, or files. |
| CWE-552 | The product makes files or directories accessible to unauthorized actors, even though they should not be. |