PHP remote file inclusion in the assign_resume_tpl method in Application/Common/Controller/BaseController.class.php in 74CMS before 6.0.48 allows remote code execution.
Link | Tags |
---|---|
https://github.com/BigTiger2020/74CMS/blob/main/README.md | third party advisory exploit |
http://www.74cms.com/news/show-2497.html | exploit vendor advisory |