In Jspxcms 9.0.0, a vulnerable URL routing implementation allows remote code execution after logging in as web admin.
The product does not restrict or incorrectly restricts access to a resource from an unauthorized actor.
Link | Tags |
---|---|
https://gitee.com/jspxcms/Jspxcms/releases | third party advisory release notes |
http://www.jspxcms.com/jspbb/question/770 | vendor advisory |