CuppaCMS v1.0 was discovered to contain a local file inclusion via the url parameter in /alerts/alertConfigField.php.
The product imports, requires, or includes executable functionality (such as a library) from a source that is outside of the intended control sphere.
Link | Tags |
---|---|
https://github.com/CuppaCMS/CuppaCMS/issues/25 | issue tracking exploit third party advisory |
https://github.com/hansmach1ne/MyExploits/tree/main/Multiple_LFIs_in_CuppaCMS_alerts | third party advisory exploit |
https://github.com/CuppaCMS/CuppaCMS/issues/15 | issue tracking exploit third party advisory |