In taocms 3.0.1 after logging in to the background, there is an Arbitrary file download vulnerability at the File Management column.
The product makes files or directories accessible to unauthorized actors, even though they should not be.
Link | Tags |
---|---|
https://github.com/taogogo/taocms/issues/10 | third party advisory exploit |